#GhostSecret

Incident/Operation

2018-04-24 • Analyzing Operation GhostSecret: Attack Seeks to Steal Data Worldwide

Operation GhostSecret was a global cyber-espionage and data-reconnaissance campaign active in March 2018 against critical infrastructure, entertainment, finance, healthcare, telecommunications, and other industries. McAfee associated the activity with the state-sponsored Hidden Cobra group through implants, tooling, and infrastructure linked to earlier operations. The campaign deployed multiple malware variants, including a previously unknown implant resembling Bankshot and the undocumented Proxysvc implant. Code relationships to Destover, reused command-and-control infrastructure, and shared certificates connected the operation to earlier Hidden Cobra activity, while its broad targeting and implant capabilities indicate an objective of covert information theft.

Tagged Reports

« Back