
Same Packer, Four Years: Gh0st RAT Toolchain Refuses to Retool
Five files and one domain tied to a Farfli/Gh0st cluster show identical PEiD packing and YARA fingerprints spanning a 2022 dropper batch and fresh September 2026 samples. A hidden rootkit driver signed with a now-blocklisted certificate and a single QQ-branded C2 domain round out a kit that appears to have needed no meaningful retooling in four years.
Three Farfli/Gh0st droppers submitted four years apart — one first seen in April 2022, two more that surfaced fresh on September 18, 2026 — carry the identical PEiD packing signature and trip the same Elastic-authored detection logic, a rule called Windows_Trojan_Generic_9e4bb0ce. That kind of toolchain stasis, more than any single new sample, is the story in this cluster: an operator that built a packer wrapper and a Gh0st-derivative payload once and has evidently seen no operational need to…
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read