Operation Navy Ghost is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
Operation Navy Ghost is a threat campaign tracked across 1 threat cluster and 3 intelligence report mentions on ThreatCluster. First observed June 30, 2026; most recent activity June 30, 2026.
A malware campaign named Operation Navy Ghost has been targeting Python developers creating Telegram bots by distributing trojanized forks of the popular Pyrogram library. Between November 2025 and June 2026, at least…
Operation Navy Ghost is a threat campaign tracked by ThreatCluster, appearing in 1 threat cluster built from 3 intelligence report mentions.
The most recent intelligence report mentioning Operation Navy Ghost on ThreatCluster is dated June 30, 2026.
Across ThreatCluster reporting, Operation Navy Ghost most frequently co-occurs with Malware, Supply Chain Attack, Trojan, CWE-78 - OS Command Injection, CWE-798 - Use of Hard-coded Credentials, among 12 tracked related entities.
The most significant recent cluster is “Operation Navy Ghost Targets Telegram Bot Developers with Malicious PyPI Packages” (3 articles · Updated June 30, 2026). Operation Navy Ghost appears across 1 threat cluster in total, listed above with sources.
Operation Navy Ghost appears in 3 intelligence report mentions across 1 deduplicated threat cluster, aggregated from 17,000+ monitored sources.