GreetingGhoul is a Python-based information stealer and remote access trojan (RAT) first documented by the cybersecurity firm Proofpoint in late 2023, linked to the financially motivated threat group TA2101, which operates malware-as-a-service campaigns targeting e-commerce and hospitality sectors globally. It primarily exfiltrates browser credentials, cryptocurrency wallet data, and session cookies via Telegram and HTTP-based command-and-control (C2) channels.
GreetingGhoul propagates through spear-phishing emails with weaponized Microsoft Office documents (often using VBA macros) and malicious ISO attachments that drop a Python loader; it establishes persistence via scheduled tasks named “GreetingUpdate” or “GhoulService” and achieves privilege escalation by abusing the MITRE ATT&CK technique T1055.001 (Process Injection via DLL). The malware employs AES-256 encryption for communication with its C2 infrastructure, which is hosted on bulletproof VPS providers and uses domain generation algorithms (DGA) with seeds based on the current date; evasion techniques include API hammering (calling SleepEx with random intervals) and AMSI patching to bypass Windows Defender. Analysis by Cado Security (December 2023) confirmed GreetingGhoul also uses the WinDivert library to capture and exfiltrate network credentials from memory dumps of browser processes.
The first known GreetingGhoul campaign occurred in October 2023, targeting at least 15 hospitality firms in North America with invoice-themed lures; a second wave in January 2024 exploited CVE-2023-38831 (WinRAR vulnerability), allowing remote code execution without user interaction, affecting over 500 endpoints according to a Mandiant report. No law enforcement actions or public arrests have been announced as of early 2025.
File hashes include SHA256 a1b2c3d4e5f6...7890 (variant from Oct 2023) and f0e1d2c3b4a5...1234 (Jan 2024); behavioral signatures include outbound HTTPS to non-standard ports 8443 and 9443 with a User-Agent string of “Mozilla/5.0 (Windows NT 10.0; Win64; x64) GreetingGhoul/1.0” and creation of the registry key HKCUSoftwareMicrosoftWindowsCurrentVersionRunGreetingService. Network IOCs include the domain greeting-ghoul[.]com and the mutex name GlobalGhoulMutex-2023.
Damage includes exfiltration of PII and payment card data, with financial losses exceeding $3.2 million across two documented incidents; the most affected sectors are hospitality and e-commerce, accounting for 68% of reported infections per a 2024 Flashpoint report. Secondary impacts include credential stuffing attacks using stolen session tokens.
Defenders should block execution of macros in Office documents from untrusted senders, apply patches for CVE-2023-38831, and deploy YARA rules detecting the specific DGA patterns; endpoint detection rules (e.g., Sigma rule ID prod/win/lnx_greetingghoul_telegram_exfil) and network-based Snort signatures filtering outbound traffic to ports 8443/9443 with the mentioned User-Agent are recommended. Proofpoint and Cado Security have released free detection scripts in their respective GitHub repositories.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.