SugarGh0st RAT Used to Target American Artificial Intelligence Experts


Proofpoint recently identified a SugarGh0st RAT campaign targeting organizations in the United States involved in artificial intelligence efforts, including those in academia, private industry, and government service.

Proofpoint tracks the cluster responsible for this activity as UNK_SweetSpecter. SugarGh0st RAT is a remote access trojan, and is a customized variant of Gh0stRAT, an older commodity trojan typically used by Chinese-speaking threat actors. SugarGh0st RAT has been historically used to target users in Central and East Asia, as first reported by Cisco Talos in November 2023.

Read more…
Source: ProofPoint


Sign up for our Newsletter


Related:

  • Swipe left: Snoops use dating apps to hook sources, says Australian Five Eyes boss

    February 10, 2022

    Nations running online foreign influence campaigns have turned to dating apps to recruit people privy to sensitive information, according to the director general of the Australian Security and Intelligence Organisation (ASIO), the nation’s security agency directed against external threats and a key partner in the Five Eyes security alliance. “In the last two years, thousands of ...

  • Israel Police Used NSO’s Pegasus Spyware Against Top Gov’t Officials, Journalists and Activists

    February 7, 2022

    Israel Police used NSO’s Pegasus spyware to hack the phones of public figures, including protest leaders, journalists, government employees and associates of former Prime Minister Benjamin Netanyahu, according to a report by Calcalist on Monday. According to the report, the hacking tool was used without a court order and against Netanyahu’s son, Avner Netanyahu, co-defendant in ...

  • Actinium hacking group is targeting emergency response and security organizations in Ukraine

    February 7, 2022

    Microsoft has detailed recent hacking activity of cyber actors, most likely aligned with the Russian Federal Security Service (FSB), who have targeted Ukraine government, security agencies and aid organizations. Microsoft says the hacking group, which it calls Actinium, has “targeted or compromised accounts” at Ukraine emergency response organizations since October. Actinium hackers also targeted organizations that ...

  • China suspected in hack of journalists at News Corp

    February 4, 2022

    Digital intruders broke into News Corp email accounts and compromised the data of an unspecified number of journalists, the company disclosed Friday. The media firm’s internet security adviser said the hack was likely aimed at gathering intelligence for Beijing’s benefit. News Corp, which publishes the Wall Street Journal, said the breach was discovered in late January and ...

  • Iranian APT MuddyWater targets Turkish users via malicious PDFs, executables

    January 31, 2022

    MuddyWater has conducted various campaigns against entities spread throughout the U.S.A, Europe, Middle East and South Asia. A typical TTP employed by the group is the heavy use of scripting in their infection chains using languages like PowerShell and Visual Basic coupled with the frequent use of living-off-the-land binaries (LoLBins). Cisco Talos recently observed a campaign operated ...

  • NSO Group Pegasus Spyware Aims at Finnish Diplomats

    January 31, 2022

    The controversial Pegasus spyware, developed by NSO Group, has been found on the devices of Finland’s diplomatic corps serving outside the country as part of a wide-ranging espionage campaign, according to Finnish officials. They also said the infections were of the zero-click variety. “The highly sophisticated malware has infected users’ Apple or Android telephones without their noticing ...