#GhostSecret
Incident/Operation
Operation GhostSecret was a global cyber-espionage and data-reconnaissance campaign active in March 2018 against critical infrastructure, entertainment, finance, healthcare, telecommunications, and other industries. McAfee associated the activity with the state-sponsored Hidden Cobra group through implants, tooling, and infrastructure linked to earlier operations. The campaign deployed multiple malware variants, including a previously unknown implant resembling Bankshot and the undocumented Proxysvc implant. Code relationships to Destover, reused command-and-control infrastructure, and shared certificates connected the operation to earlier Hidden Cobra activity, while its broad targeting and implant capabilities indicate an objective of covert information theft.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days