Skip to content
THE HUNTER’S LEDGER
Named Actor
Vova75Rus
GHOST cryptojacker kit author, selling a ComfyUI exploitation and mining kit to customer operators with a monitoring bot baked into every deployment
Status
Active
Attribution to this handle
HIGH 88%
First observed
25 May 2026
Last updated
4 Jun 2026
Operator language
Russian (a Russian-language dedication page; region code 75 in the handle read as Zabaykalsky Krai, probable)
Motivation
Financial, kit sales to cryptojacking operators
Note on named actors: Vova75Rus is a self-identifying handle, not a real-world identity. The linked report attributes the activity to this handle at HIGH confidence on the evidence it sets out, and says what would raise or lower that figure. No UTA designation was assigned because the attribution clears the bar for naming; the person behind the handle is not established.

Summary

The author of the GHOST cryptojacker kit, identified through a five-year GitHub account whose repositories the kit pulls from, a supply-chain monitoring Telegram bot present in every customer deployment, and a byte-identical rootkit binary across two customer hosts. GitHub suspended the account at the account level the day the report published. The real-world identity behind the handle is not established, which is what keeps the figure below DEFINITE.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Sells the kit rather than running it; the customers' targeting (exposed ComfyUI and GPU-cloud hosts) is on their own pages.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

handle Vova75Rus GitHub handle the kit's payload repository and nine others were published under
account-id 73169104 GitHub user id behind the handle, carried in every commit's noreply address
bot 8415540095 OWNER Telegram bot baked into every customer deployment as the author's supply-chain monitor

Infrastructure and tooling

Primary host
None: the reports anchor this actor on the accounts and artifacts above, not on a host. Hosts belong to the customer operators' pages where the report separates them.
Tooling
GHOST cryptojacker kitComfyUI-Shell-Executor

MITRE ATT&CK

20 techniques across 9 tactics, read from the mapping tables of the reports about this actor, which keep their mapping on the companion detection page. Each technique links to where it is mapped. Download this actor's Navigator layer to open the same techniques in ATT&CK Navigator, or the site-wide layer for the whole corpus.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.