GhostEmperor
Actor Type | Nation State |
---|---|
Attributed to Nation | China |
Directly Linked Intrusion Sets | Earth Estries , Salt Typhoon , FamousSparrow , Operator Panda |
GhostEmperor is an advanced attacker originally identified by researchers from Kaspersky in 2021. The group has been observed using advanced malware such as a Windows kernel mode rootkit (Demodex) and sophisticated multi-stage framework for remote access.
GhostEmperor has been observed targeting government and telecommunications entities in South East Asia and beyond.
Kaspersky attribute the group as a Chinese-speaking threat actor.
Cyber Threat Graph Context
Explore how this Intrusion Set relates to the wider threat graph
GhostEmperor Threat Reports
Report
GhostEmperor: From ProxyLogon to kernel mode
Public APT reporting from Kaspersky which outlines the GhostEmperor threat actor, including details of victimology and tooling. GhostEmperor is a ...