SYMBOLCOMMON_NAMEaka. SYNONYMS
win.hanghost (Back to overview)

HanGhost


According to ANY.RUN, this is a multi-staged loader that uses in-memory loaded .NET assembly code to download a PNG, from which the payload to be delivered is extracted.

References
2026-04-13khr0x
Tweet about HanGhost
HanGhost

There is no Yara-Signature yet.