- Status
- Active
- Attribution to this handle
- HIGH 88%
- First observed
- 25 May 2026
- Last updated
- 4 Jun 2026
- Operator language
- Russian (a Russian-language dedication page; region code 75 in the handle read as Zabaykalsky Krai, probable)
- Motivation
- Financial, kit sales to cryptojacking operators
Note on named actors: Vova75Rus is a self-identifying handle, not a real-world identity. The linked report attributes the activity to this handle at HIGH confidence on the evidence it sets out, and says what would raise or lower that figure. No UTA designation was assigned because the attribution clears the bar for naming; the person behind the handle is not established.
Summary
The author of the GHOST cryptojacker kit, identified through a five-year GitHub account whose repositories the kit pulls from, a supply-chain monitoring Telegram bot present in every customer deployment, and a byte-identical rootkit binary across two customer hosts. GitHub suspended the account at the account level the day the report published. The real-world identity behind the handle is not established, which is what keeps the figure below DEFINITE.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
Sells the kit rather than running it; the customers' targeting (exposed ComfyUI and GPU-cloud hosts) is on their own pages.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
Vova75Rus
GitHub handle the kit's payload repository and nine others were published under
73169104
GitHub user id behind the handle, carried in every commit's noreply address
8415540095
OWNER Telegram bot baked into every customer deployment as the author's supply-chain monitor
Infrastructure and tooling
- Primary host
- None: the reports anchor this actor on the accounts and artifacts above, not on a host. Hosts belong to the customer operators' pages where the report separates them.
- Tooling
MITRE ATT&CK
20 techniques across 9 tactics, read from the mapping tables of the reports about this actor, which keep their mapping on the companion detection page. Each technique links to where it is mapped. Download this actor's Navigator layer to open the same techniques in ATT&CK Navigator, or the site-wide layer for the whole corpus.
Related designations
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.