Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors GhostNet

Also known as: Snooping Dragon

Description

Cyber espionage is an issue whose time has come. In this second report from the Information Warfare Monitor, we lay out the findings of a 10-month investigation of alleged Chinese cyber spying against Tibetan institutions. The investigation, consisting of fieldwork, technical scouting, and laboratory analysis, discovered a lot more. The investigation ultimately uncovered a network of over 1,295 infected hosts in 103 countries. Up to 30% of the infected hosts are considered high-value targets and include computers located at ministries of foreign affairs, embassies, international organizations, news media, and NGOs. The Tibetan computer systems we manually investigated, and from which our investigations began, were conclusively compromised by multiple infections that gave attackers unprecedented access to potentially sensitive information. Attacks on the Dalai Lama’s Private Office The OHHDL started to suspect it was under surveillance while setting up meetings be-tween His Holiness and foreign dignitaries. They sent an email invitation on behalf of His Holiness to a foreign diplomat, but before they could follow it up with a courtesy telephone call, the diplomat’s office was contacted by the Chinese government and warned not to go ahead with the meeting. The Tibetans wondered whether a computer compromise might be the explanation; they called ONI Asia who called us. (Until May 2008, the first author was employed on a studentship funded by the OpenNet Initiative and the second author was a principal investigator for ONI.)

AI Analysis

· 2 weeks ago

Executive Summary

GhostNet, also known as Snooping Dragon, is a cyber espionage group believed to originate from China. They primarily target high-value assets across various sectors including government, media, NGOs, and diplomatic entities. Their activities are focused on gathering sensitive geopolitical information for intelligence purposes.

Goals & Targeting

GhostNet's primary goal is cyber espionage, focusing on gathering sensitive information from governments, NGOs, and international organizations. Their targeting strategy is driven by geopolitical interests, particularly in regions considered vital to Chinese strategic objectives. The group's focus on high-value targets reflects an intent to influence policy-making and diplomatic processes.

Enhanced Description

GhostNet emerged in 2009 as part of an investigation into alleged Chinese cyber espionage against Tibetan institutions. The group has been known to infect over 1,295 hosts across 103 countries, with significant concentrations in ministries, embassies, and international organizations. Their operations are characterized by advanced persistent threat (APT) tactics, including long-term access and data exfiltration. GhostNet's sophisticated campaigns often involve tailored attacks using zero-day exploits and spear-phishing emails, enabling them to maintain undetected presence for extended periods. Despite being linked to the 2009 investigation, new variants of their malware continue to emerge, underscoring their adaptability and operational continuity.

Key Capabilities

  • Nation-state sponsored cyber espionage
  • Zero-day exploit development
  • Spear-phishing campaigns
  • Custom backdoors for undetected access
  • Covert command and control infrastructure
  • Network propagation and lateral movement
  • Data exfiltration techniques
  • Long-term, low-activity campaigns

MITRE ATT&CK Tactics

Espionage
Impact
Reconnaissance
Collection

ATT&CK Techniques

T1036.001
T1040.002
T1059.003
T1078.001
T1071.001
T1074
T1566.001

Software / Tooling

Custom backdoor malware (e.g., Trojan.Qbot)
Cobalt Strike for C2 communication
Mimikatz for credential dumping
SMB protocol abuse tools
Living-off-the-land frameworks

Campaigns & Victims

GhostNet's campaigns are characterized by their persistence and adaptability. They often initiate attacks through spear-phishing emails and exploit kits to establish initial access, followed by lateral movement within the network. Notable operations include targeting the Dalai Lama’s private office in 2008-2009 and compromising Tibetan institutions.

IOC Patterns

  • Spear-phishing emails with Chinese language content
  • Distribution of malicious Office documents (e.g., .doc, .xls)
  • C2 communication channels using encrypted protocols or HTTP
  • Staging infrastructure on domains mimicking legitimate entities
  • DLL injection techniques for persistence

Recommended Actions

  • Implement continuous monitoring for unusual network activity aligned with known GhostNet TTPs.
  • Regularly update software to patch known vulnerabilities exploited by APT groups.
  • Use threat intelligence feeds to block domains and IPs linked to GhostNet campaigns.
  • Conduct regular employee training on identifying and reporting suspicious emails.
  • Consider adopting MITRE's ATT&CK Defender techniques to counter GhostNet-like threats.

Suggested Tags

APT
cyber_espionage
China-linked威胁
high-value_targeting
persistent_threat

Confidence Assessment

High confidence in the assessment of GhostNet as an APT group given extensive reporting and analysis linking it to multiple high-profile compromises. However, gaps exist regarding the full extent of their toolkit and long-term operational strategy.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Government Targeting
cyber_espionage
China-linked威胁
high-value_targeting
persistent_threat

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.