SneakyChef is a likely Chinese-speaking threat actor targeting government entities with SugarGh0st RAT.
Analyst brief
SneakyChef is a likely Chinese-speaking threat actor active since at least August 2023. The group primarily targets government agencies, research institutions, and organizations globally, using SugarGh0st RAT. Their TTPs include leveraging lures disguised as scanned documents related to Ministries of Foreign Affairs and embassies, alongside rotating old and new C2 domains. Defenders should focus on monitoring for SugarGh0st RAT activity and scrutinizing diplomatic-themed email attachments for potential phishing campaigns.
SneakyChef
unknown
SneakyChef is a threat actor known for using the SugarGh0st RAT to target government agencies, research institutions, and organizations worldwide. They have been active since at least August 2023, with a focus on leveraging old and new command and control domains. The group has been observed using lures in the form of scanned documents related to Ministries of Foreign Affairs and embassies. Talos Intelligence assesses with medium confidence that the operators are likely Chinese-speaking based on language preferences and specific targets.