惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Security @ Cisco Blogs
H
Hacker News: Front Page
P
Privacy International News Feed
N
News and Events Feed by Topic
T
Threatpost
Simon Willison's Weblog
Simon Willison's Weblog
S
Schneier on Security
K
Kaspersky official blog
S
Secure Thoughts
V2EX - 技术
V2EX - 技术
Security Latest
Security Latest
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
www.infosecurity-magazine.com
www.infosecurity-magazine.com
C
CERT Recently Published Vulnerability Notes
L
Lohrmann on Cybersecurity
Jina AI
Jina AI
P
Proofpoint News Feed
AI
AI
雷峰网
雷峰网
T
Tailwind CSS Blog
Engineering at Meta
Engineering at Meta
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Recent Commits to openclaw:main
Recent Commits to openclaw:main
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 叶小钗
Webroot Blog
Webroot Blog
Apple Machine Learning Research
Apple Machine Learning Research
SecWiki News
SecWiki News
罗磊的独立博客
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
Google DeepMind News
Google DeepMind News
Cyberwarzone
Cyberwarzone
MongoDB | Blog
MongoDB | Blog
博客园 - Franky
Schneier on Security
Schneier on Security
The GitHub Blog
The GitHub Blog
S
Security Affairs
Blog — PlanetScale
Blog — PlanetScale
Last Week in AI
Last Week in AI
P
Proofpoint News Feed
月光博客
月光博客
D
Docker
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Securelist
W
WeLiveSecurity
T
Troy Hunt's Blog
A
Arctic Wolf
博客园 - 司徒正美

Security Research | Blog

Targeted Attack on Middle East Govts (Part 1) | ThreatLabz ClaudeFix: Shared Claude Chats Meet ClickFix | Zscaler Why Do F1 Teams Need Cybersecurity, and What Is AI’s Role? Indirect Prompt Injection Targets AI Agents | ThreatLabz Splunk Enterprise RCE (CVE-2026-20253) | ThreatLabz Edgecution: Malicious Edge Extension Backdoor | ThreatLabz SmartApeSG Supply Chain Attack Targets Okendo | ThreatLabz AI Generated ClickFix Attack Delivers SmartRAT | ThreatLabz What the ThreatLabz 2026 Phishing and Initial Access Report Means for the Public Sector | Zscaler Shai-Hulud: Miasma, Hades, & AI Scanner Evasion | ThreatLabz Zscaler ThreatLabz 2026 Phishing and Initial Access Report Technical Analysis of MLTBackdoor | ThreatLabz When the Scanner Starts Thinking: Learnings from Mythos & GPT 5.5 Cyber in Security Testing | Zscaler OpenClaw Skill Distributes Remcos & GhostLoader | ThreatLabz Tropic Trooper: AdaptixC2 + Custom Beacon | ThreatLabz Do not delete blog (testing) | Zscaler Payouts King Takes Aim at the Ransomware Throne | ThreatLabz The Alibaba Incident and Why Zero Trust Matters More Than Ever In-Memory Loader Drops ScreenConnect | ThreatLabz Supply Chain Attacks Surge in March 2026 | ThreatLabz Claude Code Leak: Critical AI Security Threat 2026 Latest Xloader Obfuscation Code & C2 Protocol | ThreatLabz CVE-2026-20131: Analysis of FMC RCE | ThreatLabz Technical Analysis of SnappyClient | ThreatLabz China-nexus Group Targets Arabian Gulf Region | ThreatLabz Middle East Conflict Fuels Cyber Attacks | ThreatLabz Dust Specter APT Targets Gov’t Officials in Iraq | ThreatLabz APT37 Adds New Tools For Air-Gapped Networks | ThreatLabz GuLoader Malware Obfuscation Techniques Analyzed GuLoader Obfuscation Analysis | ThreatLabz Technical Analysis of Marco Stealer | ThreatLabz Latest Public Sector AI Adoption Trends: What Government, Healthcare, and Education Security Teams Need to Know | Zscaler Operation Neusploit: APT28 Uses CVE-2026-21509 | ThreatLabz 7 Predictions for 2026 | Zscaler SHEETCREEP, FIREPOWER, and MAILCREEP Analysis | ThreatLabz AI is Now Default Enterprise Accelerator: Takeaways from ThreatLabz 2026 AI Security Report | Zscaler GOGITTER, GITSHELLPAD, and GOSHELL Analysis | ThreatLabz Malicious NPM Packages Deliver NodeCordRAT | ThreatLabz What’s Powering Enterprise AI in 2025: ThreatLabz Report Sneak Peek | Zscaler BlindEagle Deploys Caminho and DCRAT | ThreatLabz Technical Analysis of the BlackForce Phishing Kit | ThreatLabz React2Shell RCE Vulnerability (CVE-2025-55182) | ThreatLabz Shai-Hulud V2 Poses Risk to NPM Supply Chain | ThreatLabz Technical Analysis of Matanbuchus 3.0 | ThreatLabz In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered CVE-2025-50165: Windows Graphics Component Flaw | ThreatLabz Mobile, IoT, and OT Risks Converge in the Public Sector | Zscaler Industry Attacks Surge, Mobile Malware Spreads: The ThreatLabz 2025 Mobile, IoT & OT Report | Zscaler Zscaler Discovers Vulnerability in Keras Models Allowing Arbitrary File Access and SSRF (CVE-2025-12058) | Zscaler F5 Security Incident Advisory | Zscaler Under the Radar: How Non-Web Protocols Are Redefining the Attack Surface | Zscaler SEO Poisoning Targets Ivanti VPN: Credential Theft Alert Cisco Firewall and VPN Zero Day Attacks | ThreatLabz COLDRIVER Adds BAITSWITCH and SIMPLEFIX | ThreatLabz YiBackdoor: Linked to IcedID and Latrodectus | ThreatLabz Technical Analysis of Zloader Updates | ThreatLabz Mitigating Risks from the Shai-Hulud NPM Worm | ThreatLabz Malicious PyPI Packages Deliver SilentSync RAT | ThreatLabz Technical Analysis of SmokeLoader Version 2025 | ThreatLabz Technical Analysis of kkRAT | ThreatLabz APT37: Rust Backdoor & Python Loader | ThreatLabz Anatsa’s Latest Updates | ThreatLabz Termncolor and Colorinal Explained | ThreatLabz GenAI Used to Impersonate Brazil’s Govt Websites | ThreatLabz Tracking Updates to Raspberry Robin | ThreatLabz Ransomware Surges, Extortion Escalates: ThreatLabz 2025 Ransomware Report | Zscaler CVE-2025-53770 | ThreatLabz Black Hat SEO Poisoning Search Engine Results For AI | ThreatLabz
China-nexus APT Targets the Tibetan Community | ThreatLabz
2025-07-23 · via Security Research | Blog

Operation GhostChat

In June 2025, threat actors carried out a strategic web compromise by replacing the legitimate link, tibetfund.org/90thbirthday, on a compromised webpage with a malicious link. The original link directed users to a page inviting members of the Tibetan community to send greetings to the Dalai Lama, but the malicious link redirected them to a fraudulent page hosted at thedalailama90.niccenter[.]net. This fake page was designed to closely mimic the original tibetfund.org site.

The figure below compares the legitimate webpage and the malicious replica created by the threat actor.

A side-by-side comparison of the legitimate Tibetan webpage and the malicious replica created by the threat actor.

Figure 1: A side-by-side comparison of the legitimate Tibetan webpage and the malicious replica created by the threat actor.

The malicious webpage includes an option to download an encrypted chat application, designed to lure the targeted user to connect with other members of the Tibetan community under the pretense of secure communication. Clicking on this “chat” option redirects users to tbelement.niccenter[.]net, where they are prompted to download a backdoored version of Element, a popular open-source encrypted chat application.

The figure below shows the webpage created by the threat actor which impersonates the Element messaging application to lure users.

Webpage crafted by threat actor to distribute a backdoored version of the Element messaging application.

Figure 2: Webpage crafted by threat actor to distribute a backdoored version of the Element messaging application.

The webpage also contains JavaScript code designed to collect the visitor’s IP address and user-agent information. Using WebRTC, the malicious webpage retrieves the user’s IP address and then sends the information collected via an HTTP POST request to save_ip.php, a PHP script hosted on the same server.

The figure below shows the JavaScript code responsible for this action.

The JavaScript code on the webpage used to collect the user's IP address and user-agent information.

Figure 3: The JavaScript code on the webpage used to collect the user's IP address and user-agent information.

When the user clicks the “Download” button on the webpage shown in Figure 2, a ZIP archive is downloaded from the following URL: https://tbelement.niccenter[.]net/Download/TBElement.zip.

TBElement.zip contains multiple components related to the legitimate messaging application, Element. However, the legitimate DLL, ffmpeg.dll, has been replaced with a malicious DLL. Since the legitimate, digitally signed file Element.exe is vulnerable to DLL sideloading, it automatically loads the malicious ffmpeg.dll when it runs.

The figure below shows the multiple stages involved in the attack chain.

Multi-stage attack chain for Operation GhostChat.

Figure 4: Multi-stage attack chain for Operation GhostChat.

The technical analysis below describes each stage of the attack chain and how GhostChat orchestrates command-and-control (C2) communication.

Stage 1: Shellcode loader

The ffmpeg.dll file is a stage 1 loader that loads embedded shellcode, injects it into a target process, and executes it. In addition, ffmpeg.dll creates persistence on the compromised machine by adding a Windows registry value.

The table below describes the key functionalities of the ffmpeg.dll file.

Capability

Description

API resolution

API names are stored as plain text in the binary, with no hashing algorithms used. To resolve API addresses, the export directory of the loaded module is scanned and compared against the API names.
 

The threat actors use less common Windows native APIs like Nt* and Rtl*, likely to evade detection by EDR solutions that focus on monitoring user-mode APIs for suspicious activity.

Map ntdll from disk

The stage 1 shellcode loader uses a technique to bypass potential user-mode API hooks or memory breakpoints in ntdll.dll. It achieves this by loading a fresh copy of ntdll.dll from disk and mapping it into memory. Here’s how the process works:
 

  1. Locates the base address of ntdll.dll in the process's memory using K32GetModuleInformation.
  2. Maps a fresh copy of ntdll.dll into memory from its default path, C:\Windows\System32\ntdll.dll. This path is hardcoded in the binary.
  3. Locates the .text section of the currently loaded ntdll.dll by walking through its PE header in memory.
  4. Resolves the address of the VirtualProtect API and uses it to change the memory protection of the .text section to PAGE_EXECUTE_READWRITE.
  5. Overwrites the .text section of the loaded ntdll.dll with the .text section of the fresh copy mapped from disk.
  6. Restores the original memory protection settings of the .text section using VirtualProtect.
     

This process ensures that any API hooks or modifications added by endpoint security solutions in the user-mode ntdll.dll are overwritten.

Code injection

The stage 1 shellcode loader uses shared memory section-based code injection to inject 32-bit shellcode into a legitimate Windows process, ImagingDevices.exe. The technique relies on low-level APIs to minimize detection by security solutions. The steps are as follows:
 

  1. Creates a memory section in the current process using NtCreateSection with PAGE_EXECUTE_READWRITE protection.
  2. Maps the section into the current process using NtMapViewOfSection.
  3. Creates the target process (ImagingDevices.exe) using RtlCreateUserProcess.
  4. Maps the earlier created memory section into the target process using NtMapViewOfSection.
  5. Writes shellcode to the shared memory section within the current process using NtWriteVirtualMemory, making the shellcode appear in the target process's memory.
  6. Creates a thread in the target process with its function pointing to the mapped section containing the shellcode using RtlCreateUserThread.
     

This method stealthily injects the shellcode into the target process.

Registry persistence

To achieve persistence, the malware adds a registry value under the path:
 

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
 

  • Key Name: Element
  • Value: Path to the malicious Element.exe binary

Table 1: Key capabilities of the ffmpeg.dll file.

Stage 2: Reflective loader

The stage 2 shellcode contains an executable compressed with NRV2D, which is one of the compression algorithms supported by the popular UPX packer. To evade detection, the executable’s PE headers have their MZ and PE magic bytes replaced with 0xd and 0xa.

The shellcode allocates memory with PAGE_EXECUTE_READWRITE permissions via VirtualAlloc, reflectively loads the stage 3 executable into this memory region, and then executes it starting at its entry point.

Stage 3: Ghost RAT

The stage 3 executable is a variant of Ghost RAT. Its embedded configuration is encrypted with a custom algorithm resembling RC4 but modified significantly. This implementation adds bitwise operations, and its Key Scheduling Algorithm (KSA) is altered so the provided key does not affect encryption or decryption. Python code to decrypt the configuration is available in our GitHub repository.

C2 communication

Ghost RAT communicates with its C2 server at 104.234.15[.]90:19999 using a TCP binary protocol. This variant features a custom packet header that uses "KuGou" instead of the usual "Gh0st" and encrypts its traffic using the same RC4-like algorithm used for the configuration encryption.

Malicious functionality is largely implemented in the exported functions of a plugin DLL named config.dll. This DLL is downloaded from the C2 server and stored on disk at C:\Users\Public\Documents\config.dll. To evade static AV scans, the DLL is XOR-encoded with a one-byte key (0x15) and decoded only upon being loaded by the malware.

As the exact DLL couldn’t be retrieved from the C2 server, its functionality was derived by analyzing a KuGou variant DLL (MD5: 7b9a808987d135e381f93084796fd7c1) and comparing it with the Ghost RAT’s source code.

A table outlining the C2 commands supported by this variant is shown below.

Command ID

Functionality

Source code class

0x0

Sets a flag to indicate a successful connection to the C2.

CKernelManager

0x1

Executes the DllFile export in the plugin DLL. Supports file manipulation sub-commands.

CFileManager

0x2

Executes the DllScreen export in the plugin DLL. Supports screen capture and clipboard manipulation sub-commands.

CScreenManager

0x3

Executes the DllVideo export in the plugin DLL. Supports webcam video capture sub-commands.

CVideoManager

0x4

Executes the DllKeybo export in the plugin DLL. Supports keylogging-related sub-commands.

CKeyboardManager

0x5

Executes the DllAudio export in the plugin DLL. Supports audio recording and playback.

CAudioManager

0x6

Executes the DllSyste export in the plugin DLL. Supports process and window manipulation sub-commands. 

CSystemManager

0x7

Executes the DllShell export in the plugin DLL. Supports remote shell via command prompt.

CShellManager

0x8

Retrieves SeShutdownPrivilege to shut down the victim’s system with ExitWindowsEx.

N/A

0x9

Terminates itself.

N/A

0xD

Sets the HKLM\SYSTEM\CurrentControlSet\Services\Apache\Host value. This value likely serves as a nickname for the threat actor to identify this system.

N/A

0xF

Sets the HKLM\SYSTEM\CurrentControlSet\Services\Apache\ConnectGroup value. This value is likely used by the threat actor for organizing infected machines.

N/A

0x13

Executes the DllMsgBox export in the plugin DLL. Displays a message box with an attacker-specified message and title.

N/A

0x14

Sends the plugin DLL path hardcoded in the sample C:\Users\Public\Documents\config.dll path to the C2. Supports plugin DLL management sub-commands.

N/A

0x15

Executes DllSerSt export in the plugin DLL. Supports system administration sub-commands including user account manipulation.

CSysInfo

0x16

Executes the DllSerMa export in the plugin DLL. Supports Windows service manipulation sub-commands.

CSerManager

0x17

Executes the DllReg export in the plugin DLL. Supports Windows registry manipulation sub-commands.

CRegistry

Table 2: List of commands supported by the KuGou variant of Ghost RAT.

Explore more Zscaler blogs

A panda logo surrounded by glowing stars.

Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1

A panda in a cloak set against a digital map.

Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2

An image of a bright moon and starry night above a dark forest.

DodgeBox: A deep dive into the updated arsenal of APT41 | Part 1

A large glowing moon reflecting over a body of water.

MoonWalk: A deep dive into the updated arsenal of APT41 | Part 2

A person working from home on their computer.

From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West