GhostNet
Also reported as Snooping Dragon. Linked to China by one source.
Reports per quarter
Techniques seen in the last two years
- T1010 1 report
- T1016 1 report
- T1027.010 1 report
- T1041 1 report
- T1056.001 1 report
- T1057 1 report
- T1059 1 report
- T1059.005 1 report
- T1059.006 1 report
- T1059.007 1 report
Show all 24 techniques Show fewer
Counts come from technique IDs in the actor's report text.
CVEs named in reports
- CVE-2007-4848
- CVE-2008-3869
- CVE-2008-3870
- CVE-2009-0927 KEV
- CVE-2009-4324 KEV
- CVE-2010-0249 KEV
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2010-3654
- CVE-2011-2462 KEV
- CVE-2011-3544 KEV
- CVE-2012-0158 KEV ransomware
Show all 30 CVEs Show fewer
- CVE-2012-0507 KEV ransomware
- CVE-2012-1723 KEV ransomware
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2013-0422 KEV ransomware
- CVE-2016-1646 KEV
- CVE-2016-5198 KEV
- CVE-2017-5030 KEV
- CVE-2017-5070 KEV
- CVE-2018-17463 KEV
- CVE-2018-17480 KEV
- CVE-2018-6065 KEV
- CVE-2019-5825 KEV
- CVE-2022-30190 KEV ransomware
- CVE-2023-34362 KEV ransomware
- CVE-2024-1708 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-4577 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Ghost RAT (Malware Family)
-
GhostNet, Snooping Dragon - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor GhostNet, Snooping Dragon - Threat Group Cards: A Threat Actor Encyclopedia
-
Shadow Network - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Shadow Network - Threat Group Cards: A Threat Actor Encyclopedia
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
Advanced Persistent Threats: A Decade In Review
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Advanced Persistent Threats: A Decade In Review
Show all 33 reports Show fewer
-
Missing Link Tibetan Groups Targeted with 1-Click Mobile Exploits
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Missing Link Tibetan Groups Targeted with 1-Click Mobile Exploits
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor 10 Years Since Ghostnet
-
When Governments Hack Opponents: A Look At Actors And Technology
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor When Governments Hack Opponents: A Look At Actors And Technology
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor sec14-paper-blond
-
Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Threat Index: Characterizing And Quantifying Politically-Motivated Targeted Malware
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted_Attacks_Lense_NGO
-
Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Ke3Chang Targeted Attacks Against Ministries Of Foreign Affairs
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Sin Digoo Affair
-
The Voho Campaign: An In Depth Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Voho Campaign: An In Depth Analysis
-
The Many Faces Of Gh0St Rat: Plotting The Connections Between Malware Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Many Faces Of Gh0St Rat: Plotting The Connections Between Malware Attacks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The Lurid Downloader
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Heading 1
-
Shadows In The Cloud: Investigating Cyber Espionage 2.0
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Shadows In The Cloud: Investigating Cyber Espionage 2.0
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor In-depth Analysis of Hydraq
-
Microsoft Word - FINAL_USCC_PRC_Cyber_Capabilities_Study.docx
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Word - FINAL_USCC_PRC_Cyber_Capabilities_Study.docx
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor DECLAWING THE DRAGON
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor GhostNet
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor GhostNet
-
Tracking GhostNet: Investigating a Cyber Espionage Network
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking GhostNet: Investigating a Cyber Espionage Network
Newest first. Details opens the report in Explore.