SugarGh0st RAT is a Windowsmalware program (a customized variant of Gh0stRAT), utilized in cyberattacks since August 2023, first documented by Cisco Talos.[1][2][3][4]
It was used to attack government agencies and the private sector,[5] in EMEA and Asia (cyberespionage, surveillance campaign and data theft).[6]
In May 2024 it was reported an email phishing campaign (spotted first by Proofpoint) from threat actorSweetSpecter, using this malware, targeting US AI experts from government services, academia, US companies (for example, employees of OpenAI company), with the intention of obtaining non-public information.[7][8][9][10][11][12]