GhostEmperor

Malware type
backdoor, rootkit
Family
Malware family
Profile updated
2026-07-07 13:12:44

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:my country_code:th

Context

GhostEmperor is a sophisticated malware used by a likely APT group, targeting government and tech sectors in Asia. It employs a novel rootkit to maintain persistence and evade detection.

Detection coverage

  • 1 YARA rules

Used by threat actors

  • FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)
  • GhostEmperor/Demodex 2023 Compromise (campaign)

Detection rules

  • MALPEDIA_Win_Ghostemperor_Auto (yara-rule)

Reports & references

  • Kaspersky — 104407 (report)
  • media.kasperskycontenthub.com — Ghostemperor Technical Details Pdf Eng (report)
  • sygnia.co — Ghost Emperor Demodex Rootkit (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Ghostemperor (report)
  • kaspersky.com — 2021 Ghostemperor Chinese Speaking Apt Targets High Profile Victims Using Unknown Rootkit (report)

External references