← Back to all campaigns
ActiveMITRE ATT&CK

Operation Ghost

Operation Ghost was an APT29 campaign starting in 2013 that included operations against ministries of foreign affairs in Europe and the Washington, D.C. embassy of a European Union country. During Operation Ghost, APT29 used new families of malware and leveraged web services, steganography, and unique C2 infrastructure for each victim.

First observedSep 1, 2013
Last observedOct 1, 2019
Attributed actors1
Source-backed events3
Attribution

Who has been linked to this activity

Each relationship retains its own confidence and source.

Source ReportedActive actor

APT29

APT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research ...

mitre-attckReview source
Activity

Campaign timeline

Every date says what it measures so catalog dates are not confused with publication dates.

Cataloged
Attribution

APT29 attributed to this campaign

Attribution confidence: Source Reported.

Last observed
Campaign

Operation Ghost last observed

The campaign source marks this as the latest known activity date.

MITRE ATT&CKSource
First observed
Campaign

Operation Ghost first observed

The campaign source marks this as the beginning of the known activity window.

MITRE ATT&CKSource
About the context below

CVEs, techniques, malware, and indicators in the sections below are associated with an attributed actor. They are useful investigative context, but the campaign source does not necessarily link every item directly to this campaign.

Investigation context

What the attributed actors are known to use

Use this material to guide hunting and prioritization, then confirm each relationship against its cited source.

Malware and tools 49

  • BoomBoxMalware | APT29
  • CloudDukeMalware | APT29
  • Cobalt StrikeMalware | APT29
  • CosmicDukeMalware | APT29
  • CozyCarMalware | APT29
  • EnvyScoutMalware | APT29
  • FatDukeMalware | APT29
  • FoggyWebMalware | APT29
  • GeminiDukeMalware | APT29
  • GoldFinderMalware | APT29
  • GoldMaxMalware | APT29
  • HAMMERTOSSMalware | APT29

Indicators 0

No source-linked indicators are available.

Sources

Evidence behind this page

Open the original material before making an attribution or response decision.

Continue investigating

Campaigns with shared actors