rghost is owned by the person who is performing the wave of account hacking.
Not saying you're wrong, but what drove you to that conclusion?
The fact that almost every single known phishing account that has posted download links to that site...?
That doesn't really indicate anything apart from the fact that the phisher likes RGhost for some reason.
RGhost seems to be an actual working file sharing service. If its owner used it for phishing attempts, that would be a very dumb move...