kit
GHOST cryptojacker kit
A Linux cryptojacking kit with an LD_PRELOAD rootkit, competitor-killing and self-spreading stages, run by more than one operator. Named by 2 reports, 11 detection rules, 1 IOC feed and 2 tracked actors.
Also written as: GHOST-cryptojacker-kit, GHOST-Cryptojacker-Kit, GHOST-Cryptojacker-LDPreload-Rootkit, GHOST v5.1/v6.0. These are the spellings the rules, feeds and profiles use; the page collects all of them.
Reports
Detection rules
YARA rules whose family metadata names this family, by detection page.
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)
MAL_Linux_GHOST_LDPreload_Rootkit_Family
Detection rules
Multi-Actor AI-Agent Framework Abuse (8 Operators)
MAL_Linux_GHOST_Kit_Installer_Shell
Detection rules
GHOST Cryptojacker Kit — Vova75Rus Supply Chain (77.110.96.200)
MAL_Linux_GHOST_libpam_cache_Rootkit_Family, MAL_Linux_GHOST_libpam_cache_Source, MAL_Linux_GHOST_Kit_Shell_Installer, MAL_Linux_GHOST_ComfyUI_Python_Kit, MAL_Linux_GHOST_ComfyUI_Fake_PerformanceMonitor_Node, MAL_Linux_GHOST_Hysteria_Operator_Wrapper, MAL_Linux_GHOST_min1_DualTelegram_Wrapper, MAL_Linux_GHOST_check_comfyui_Scanner, MAL_Linux_GHOST_get_all_ranges_CloudEnumerator
IOC feeds
Tracked actors
Designations whose profile lists this family as tooling.
- UTA-2026-016: GHOST cryptojacker kit customer (operator A) with self-hosted mining pool proxies
- UTA-2026-017: GHOST cryptojacker kit customer (operator B) using public mining pools, host abandoned
A family name here is the label the linked rule, feed or profile carries, normalised to one spelling by _data/families.yml. Where a report declines to name a family, this page does not either.