logo

Operation_Ghoul__2016__Operation_Ghoul_targeted_attacks_on_industrial_and_engineering_organizations_-_Securelist.pdf

ID: 8f4b1976-1927-4579-b357-531d736e8b84

STIX ID: report--8f4b1976-1927-4579-b357-531d736e8b84

Threat Score

72/100

Uploaded: 2026-08-19

Published Date: 2016-08-17

Last Modified Date: 2016-08-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Ghoul is a financially motivated targeted campaign documented by Kaspersky that used spear‑phishing emails (often with 7z attachments) to deliver Hawkeye-based spyware to over 130 organizations across 30+ countries, primarily in industrial, engineering and manufacturing sectors; the malware captured keystrokes, credentials, screenshots and other sensitive data and exfiltrated it to attacker-controlled servers (notably 192.169.82.86). The report provides technical details, IoCs (MD5 hashes, domains, URLs, file paths), victim geography/industry breakdown and detection signatures, and recommends heightened email/privileged-user defenses.