Operation Navy Ghost — Campaign Analysis & Threat Activity

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
June 30, 2026
Last Seen
June 30, 2026

Operation Navy Ghost is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Operation Navy Ghost is a threat campaign tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 30, 2026; most recent activity June 30, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Checkmarx explains — checkmarx.com · June 30, 2026
  • Malicious PyPI packages give hackers control of Telegram bot servers — Bleepingcomputer · June 30, 2026
  • Malicious PyPI packages give hackers control of Telegram bot servers — Bleepingcomputer · June 30, 2026

Frequently asked questions

What is Operation Navy Ghost?

Operation Navy Ghost is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.

Is Operation Navy Ghost still active?

The most recent intelligence report mentioning Operation Navy Ghost on ThreatCluster is dated June 30, 2026.

What is Operation Navy Ghost associated with?

Across ThreatCluster reporting, Operation Navy Ghost most frequently co-occurs with Malware, Supply Chain Attack, Trojan, CWE-78 - OS Command Injection, CWE-798 - Use of Hard-coded Credentials, among 12 tracked related entities.

What are the latest developments involving Operation Navy Ghost?

The most significant recent cluster is “Operation Navy Ghost Targets Telegram Bot Developers with Malicious PyPI Packages” (3 articles · Updated June 30, 2026). Operation Navy Ghost appears across 1 threat cluster in total, listed above with sources.

How much reporting does ThreatCluster have on Operation Navy Ghost?

Operation Navy Ghost appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown