Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 15:28:13 UTC Home > List all groups > List all tools > List all groups using tool BH_A006 Tool: BH_A006 Names BH_A006 Category Malware Type Reconnaissance, Backdoor, Keylogger, Info stealer Description (BleepingComputer) BH_A006 is a heavily modified version of the Gh0st RAT backdoor, featuring many layers of obfuscation to bypass security protections and thwart analysis. Its features include network service creation, UAC bypassing, and shellcode unpacking and launching in the memory. Information Last change to this tool card: 19 July 2022 Download this tool card in JSON format All groups using tool BH_A006 Changed Name Country Observed APT groups Space Pirates 2017-Nov 2024 1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c1bd4d19-ed21-45b3-a7a3-bc81ded7effb https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=c1bd4d19-ed21-45b3-a7a3-bc81ded7effb Page 1 of 1