logo

SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques

ID: 566092bc-cd18-47bf-b304-aaca8d59f42f

STIX ID: report--566092bc-cd18-47bf-b304-aaca8d59f42f

Threat Score

75/100

Uploaded: 2026-08-19

Published Date: 2024-06-25

Last Modified Date: 2024-06-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos reports that the SneakyChef espionage actor is deploying SugarGh0st RAT in a multinational campaign against government agencies across EMEA and Asia, using decoy documents and SFX RAR delivery to drop a loader DLL and a VB script that implants SugarGh0st with C2 communication, with activity dating back to 2023 and probable Chinese-language operations.