Cybersecurity from Málaga · Networks, lures and threats

← Threats
Actor · MITRE G1045

GhostEmperor

FamousSparrowUNC2286Salt TyphoonRedMikeOPERATOR PANDA

GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a… Source: MISP

Attributed country: CN according to MISP

Activity on Jábega · 12 weeks

2 stories · first seen on 17 Sep 2026 · last seen on 17 Sep 2026

News

Appears alongside

MITRE ATT&CK techniques

Reconnaissance

Resource Development

Initial Access

Persistence

Credential Access

Lateral Movement

Collection

Command and Control

Exfiltration

Defense impairment

Relationships come from co-occurrence in the news, not attribution. Sources: MISP galaxy, MITRE ATT&CK and SigmaHQ. attack.mitre.org ↗