Elastic Security Labs is tracking Golden Gh0st RAT targeting Western companies, expanding beyond its previously documented targeting of financial organizations in the Asia-Pacific region.
Same TTPs as
@ExpelSecurity CylindricalCanine research post:
go.es.io/3TEZ0G6
The initial payload was delivered as a fake screenshot with a .pif extension, signed with a revoked certificate and hosted on myphotos[.]s[.]gy.
Follow-on payloads were staged in a public Google Cloud Storage bucket at storage[.]googleapis[.]com/nikeupdat/.
Multiple stages, and every one is either validly code-signed or never exists on disk as an executable.
Abused code-signing certificates, all valid at time of use.
Two are EV, same CA, both dated 2026-07, issued to two different "Private Organization" subjects:
- 杭州思维宇宙科技有限公司 (Hangzhou Siwei Yuzhou Technology), thumbprint: 14E0FCA3F0F656D1AF6EA66E1B2B7C6B4ACD8E2D
- Dongguan Jieshan Technology Co., Ltd, thumbprint: C29C3C494A348EA879ABFF50DD56B85E9CB6366A
IOCs:
api[.]probref[.]com:5188 (C2)
storage[.]googleapis[.]com/nikeupdat/
myphotos[.]s[.]gy
5ef6019fb6ee1db1201ee479a68669b47eb0d5d82770dbd30b05f46ccbc68f4f
b6cb6d5de2c62aa1351b1b240dc223c3d6fa95083cf43b2866d84a8a6c4d0446