GhostEmperor
- Malware type
- backdoor, rootkit
- Family
- Malware family
- Profile updated
- 2026-07-07 13:12:44
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:my country_code:th
Context
GhostEmperor is a sophisticated malware used by a likely APT group, targeting government and tech sectors in Asia. It employs a novel rootkit to maintain persistence and evade detection.
Detection coverage
- 1 YARA rules
Used by threat actors
- FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)
- GhostEmperor/Demodex 2023 Compromise (campaign)
Detection rules
- MALPEDIA_Win_Ghostemperor_Auto (yara-rule)
Reports & references
- Kaspersky — 104407 (report)
- media.kasperskycontenthub.com — Ghostemperor Technical Details Pdf Eng (report)
- sygnia.co — Ghost Emperor Demodex Rootkit (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Ghostemperor (report)
- kaspersky.com — 2021 Ghostemperor Chinese Speaking Apt Targets High Profile Victims Using Unknown Rootkit (report)