Skip to content

RAT

Ghost RAT

aka Farfli · Gh0st RAT · PCRat

According to Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan “Remote Access Tool” used on Windows platforms, and has been used to hack into some of the most sensitive computer networks

Ghost RAT, also known as Farfli, Gh0st RAT, PCRat, is a Windows rat operated by EMISSARY PANDA, Hurricane Panda and others.

Background

As described by Security Ninja, Gh0st RAT (Remote Access Terminal) is a trojan "Remote Access Tool" for Windows that has been leveraged to penetrate some of the most sensitive computer networks in the world.

Its documented capabilities include: Seizing full control of the infected bot's remote screen. Logging keystrokes both in real time and offline. Streaming a live feed from the host's webcam and microphone. Downloading remote binaries onto the infected host. Controlling remote shutdown and reboot of the host. Disabling the victim's pointer and keyboard input. Opening a fully controllable shell on the remote host. Listing all active processes. Clearing every existing hook from the SSDT.


Source: Malpedia (Fraunhofer FKIE).