GhostEmperor
FamousSparrowUNC2286Salt TyphoonRedMikeOPERATOR PANDA
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a… Fuente: MISP
País atribuido: CN según MISP
Actividad en Jábega · 12 semanas
2 noticias · vista por primera vez el 17 sept 2026 · la última, el 17 sept 2026
Noticias
- China's FamousSparrow APT Spies on US Politics in Latin AmericaDark Reading · 17 sept 2026
- FamousSparrow centra sus operaciones en América Latina y despliega el nuevo backdoor SparroWockyWeLiveSecurity · 17 sept 2026
Aparece junto a
Técnicas MITRE ATT&CK
Reconocimiento
Preparación de recursos
Acceso inicial
Persistencia
Acceso a credenciales
Movimiento lateral
Recopilación
Mando y control
Exfiltración
Defense impairment
Relaciones por coaparición en noticias, no atribución. Fuentes: MISP galaxy, MITRE ATT&CK y SigmaHQ. attack.mitre.org ↗