GhostEmperor
FamousSparrowUNC2286Salt TyphoonRedMikeOPERATOR PANDA
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a… Source: MISP
Attributed country: CN according to MISP
Activity on Jábega · 12 weeks
2 stories · first seen on 17 Sep 2026 · last seen on 17 Sep 2026
News
- China's FamousSparrow APT Spies on US Politics in Latin AmericaDark Reading · 17 Sep 2026
- FamousSparrow centra sus operaciones en América Latina y despliega el nuevo backdoor SparroWockyWeLiveSecurity · 17 Sep 2026
Appears alongside
MITRE ATT&CK techniques
Reconnaissance
Resource Development
Initial Access
Persistence
Credential Access
Lateral Movement
Collection
Command and Control
Exfiltration
Defense impairment
Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗