+ Reply to Thread
Page 1 of 4 123 ... LastLast
Results 1 to 10 of 32
  1. #1
    Retired Admin
    Join Date
    Feb 2005
    Location
    Norway
    Posts
    1,933

    Major cyberspy network uncovered.

    Major cyber spy network uncovered


    seems like they used "Ghost RAT" which source can be found at
    http://www.opensc.ws/c-c/3462-gh0st-...urce-code.html

    so is this RAT really good enough for highlevel infiltration?

  2. #2
    Retired Admin
    Join Date
    Feb 2005
    Location
    Norway
    Posts
    1,933

  3. #3
    Senior Member gangster136's Avatar
    Join Date
    Sep 2008
    Location
    C:\Windows\Gangster
    Posts
    502
    WOW. now imagin what spynet can do on all of there PC's

  4. #4
    Senior Member Berzek's Avatar
    Join Date
    Jun 2008
    Location
    DecodeBinary( 01010000 01100001 01101110 01100001 01101101 01100001 )
    Posts
    354
    I doubt they used a silly "ghost Rat" , nor "opensource rat"
    they code their own malware.
    DDR2 2GB RAM
    dc5750SmallForm|4200+2.20GHz|512MB X1300 |

  5. #5
    Senior Member mjrod5's Avatar
    Join Date
    Aug 2008
    Location
    In your stack O___O
    Posts
    3,120
    lol
    GhostRAT?
    That thing is shit..
    It was helpful to me, but not on a scale that big..
    Its ok but then again its shit. :S
    In The Oven (err in Development) : Pie
    Quote Originally Posted by uraskiddie View Post
    What are you? Like 10 years old?
    That's complete rubbish, you probably got your depictions of being a "hacker" from a prepubescent forum infested with homosexually-oriented pedophiles.
    Quote Originally Posted by Envy View Post
    Russian?
    Trusted.
    Botnets are like our right hands.
    http://cognitivity.org/

  6. #6
    Senior Member Berzek's Avatar
    Join Date
    Jun 2008
    Location
    DecodeBinary( 01010000 01100001 01101110 01100001 01101101 01100001 )
    Posts
    354
    yes, some articles says "Ghostnet" or "GhostRat" , that is to divert from the public of the true!.
    DDR2 2GB RAM
    dc5750SmallForm|4200+2.20GHz|512MB X1300 |

  7. #7
    Senior Member mjrod5's Avatar
    Join Date
    Aug 2008
    Location
    In your stack O___O
    Posts
    3,120
    I wonder if they added encryption to it.. ?
    They probably didnt and thats why they got caught ^^
    In The Oven (err in Development) : Pie
    Quote Originally Posted by uraskiddie View Post
    What are you? Like 10 years old?
    That's complete rubbish, you probably got your depictions of being a "hacker" from a prepubescent forum infested with homosexually-oriented pedophiles.
    Quote Originally Posted by Envy View Post
    Russian?
    Trusted.
    Botnets are like our right hands.
    http://cognitivity.org/

  8. #8
    Senior Member LinuZ_'s Avatar
    Join Date
    Oct 2008
    Location
    ntdll!NtQuerySystemInformation
    Posts
    549
    Anyone of you considered the chance that there might be multiple RATs with the same names?
    GhostNet sounds kinda nice, I doubt there is only 1 RAT using that name...

  9. #9
    Retired Admin
    Join Date
    Feb 2005
    Location
    Norway
    Posts
    1,933
    Ghostnet is the botnets name. They used those HTTP based bots where the interface is on a homepage where you can login and send commands to the bot.

    in addition to that they used Gh0st RAT on the bots individually to spy on it.


    according to the Gh0stnet research document:
    Control over some targeted
    machines is maintained using the Chinese gh0st RAT (Remote Access Tool). These Trojans generally
    allow for near-unrestricted access to the infected systems.
    One of the commands available to the attacker(s) instructs infected computers to download the
    gh0st RAT remote administration tool, which gives the attacker(s) full, real-time control of the infected
    computer. Gh0st RAT is an open source Trojan that is widely available online. It was developed by
    Chinese programmers but has now been translated into English. The program allows an attacker to
    create an executable fle that can be repacked and disguised and used to infect and compromise a target
    computer. This fle can be confgured to directly connect to the gh0st RAT owner or to a third location, a
    control server, when it retrieves the current IP address of the gh0st RAT owner.
    what really attracts my interest in this research is that the chinese hackers used a "NO-IP/DYNDNS"-like service that is located in China.
    We all know NO-IP nulls and closes your domain when they find out you run botnet/trojans on it. But the chinese version doesnt. They dont give a damn.
    So you can collect bots for years and keep collecting without the fear of losing them one day.
    the dns service is http://www.3322.org/ i think.
    Imma gonna get some chinese to sign up an account and domain there.
    and in exchange for their hostility i might even ddos some Tibetanian site

  10. #10
    Senior Member
    Join Date
    Jun 2008
    Location
    0x40000
    Posts
    1,528
    Quote Originally Posted by LttCoder View Post
    Ghostnet is the botnets name. They used those HTTP based bots where the interface is on a homepage where you can login and send commands to the bot.
    Whoa! I am currently busy on a project that uses the same basics:cool: Hmm,, not so bad idea after all then

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. wireless network scanner
    By LttCoder in forum Snippets
    Replies: 5
    Last Post: 15-03-2009, 08:15
  2. Add Network Share Proplem [NetShareAdd]
    By Kill3r7 in forum Delphi Help
    Replies: 5
    Last Post: 13-03-2009, 14:20
  3. Demystifying Network Attacks DoS/DDoS Edition - By xyr9x
    By xyr0x in forum Tutorials and Articles
    Replies: 9
    Last Post: 07-07-2007, 01:41
  4. Network Shutdown 1.0
    By LttCoder in forum Malware sources
    Replies: 3
    Last Post: 15-05-2007, 21:51
  5. Access to other computers over the same network ?
    By DXsTuK in forum Delphi Help
    Replies: 4
    Last Post: 11-02-2006, 11:45

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts

Search Engine Friendly URLs by vBSEO 3.6.0 ©2011, Crawlability, Inc.