SneakyChef espionage group targets government agencies with SugarGh0st and more infection techniques
ID: 566092bc-cd18-47bf-b304-aaca8d59f42f
STIX ID: report--566092bc-cd18-47bf-b304-aaca8d59f42f
Threat Score
75/100
Uploaded: 2026-08-19
Published Date: 2024-06-25
Last Modified Date: 2024-06-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Cisco Talos reports that the SneakyChef espionage actor is deploying SugarGh0st RAT in a multinational campaign against government agencies across EMEA and Asia, using decoy documents and SFX RAR delivery to drop a loader DLL and a VB script that implants SugarGh0st with C2 communication, with activity dating back to 2023 and probable Chinese-language operations.
