APTMembers
APT

Same Packer, Four Years: Gh0st RAT Toolchain Refuses to Retool

Five files and one domain tied to a Farfli/Gh0st cluster show identical PEiD packing and YARA fingerprints spanning a 2022 dropper batch and fresh September 2026 samples. A hidden rootkit driver signed with a now-blocklisted certificate and a single QQ-branded C2 domain round out a kit that appears to have needed no meaningful retooling in four years.

Sep 19, 2026, 22:37 (UTC+9)Last seenSep 19, 2026Severity94ByCTX TeamActorSalty SpiderKuKuIOC18MITRE30RegionsUS

Three Farfli/Gh0st droppers submitted four years apart — one first seen in April 2022, two more that surfaced fresh on September 18, 2026 — carry the identical PEiD packing signature and trip the same Elastic-authored detection logic, a rule called Windows_Trojan_Generic_9e4bb0ce. That kind of toolchain stasis, more than any single new sample, is the story in this cluster: an operator that built a packer wrapper and a Gh0st-derivative payload once and has evidently seen no operational need to…

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence