GhostEmperor

Aliases: FamousSparrow, UNC2286, Salt Typhoon, RedMike, OPERATOR PANDA

First seen
2020-05-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-05-13 19:25:06
Profile updated
2026-07-07 12:09:17

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:sg country_code:id country_code:th country_code:ph country_code:vn

Context

GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.

Related threat objects

Reports & references

  • cloud.google.com — Unc4841 Post Barracuda Zero Day Remediation (report)
  • Kaspersky — 104407 (report)
  • media.kasperskycontenthub.com — Ghostemperor Technical Details Pdf Eng (report)
  • ESET — Famoussparrow Suspicious Hotel Guest (report)
  • ncsc.gov.uk — Ncsc Mar Sparrowdoor (report)
  • sygnia.co — Ghost Emperor Demodex Rootkit (report)
  • wsj.com — China Cyberattack Internet Providers 260Bd835 (report)
  • recordedfuture.com — Redmike Salt Typhoon Exploits Vulnerable Devices (report)

Attributed from

  • Earth Estries Government & Technology Cyberespionage Campaign (campaign)
  • FamousSparrow/GhostEmperor Vulnerability Exploit and Post-Compromise Activity (campaign)
  • GhostEmperor/Demodex 2023 Compromise (campaign)

External references