GhostEmperor
Aliases: FamousSparrow, UNC2286, Salt Typhoon, RedMike, OPERATOR PANDA
- First seen
- 2020-05-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-05-13 19:25:06
- Profile updated
- 2026-07-07 12:09:17
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:sg country_code:id country_code:th country_code:ph country_code:vn
Context
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.
Related threat objects
- Earth Estries (threat-actor)
Reports & references
- cloud.google.com — Unc4841 Post Barracuda Zero Day Remediation (report)
- Kaspersky — 104407 (report)
- media.kasperskycontenthub.com — Ghostemperor Technical Details Pdf Eng (report)
- ESET — Famoussparrow Suspicious Hotel Guest (report)
- ncsc.gov.uk — Ncsc Mar Sparrowdoor (report)
- sygnia.co — Ghost Emperor Demodex Rootkit (report)
- wsj.com — China Cyberattack Internet Providers 260Bd835 (report)
- recordedfuture.com — Redmike Salt Typhoon Exploits Vulnerable Devices (report)
Attributed from
- Earth Estries Government & Technology Cyberespionage Campaign (campaign)
- FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)
- GhostEmperor/Demodex 2023 Compromise (campaign)