GHOSTEMPEROR
SALT TYPHOON (PARTIAL OVERLAP)
Threat IntelligenceAPTFebruary 18, 202615 min read

GhostEmperor APT: Threat Intelligence Profile

Highly sophisticated Chinese APT deploying kernel-level rootkits and advanced anti-forensic techniques to maintain persistent access in telecom and government networks.

Scroll

GhostEmperor APT (also known as GhostEmperor, Salt Typhoon (partial overlap)) is a state-sponsored advanced persistent threat group attributed to China, active since 2020. The group primarily targets telecom, government in Southeast Asia and Middle East sectors.

Overview & Attribution

Highly sophisticated Chinese APT deploying kernel-level rootkits and advanced anti-forensic techniques to maintain persistent access in telecom and government networks.

Threat Assessment

GhostEmperor APT has been active since 2020, attributed to China. The group is known for targeting telecom, government in Southeast Asia and Middle East using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

GhostEmperor APT employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on telecom, government in Southeast Asia and Middle East sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

GhostEmperor APT is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
ExecutionT1059.001 PowerShellPost-exploitation
PersistenceT1547.006 Kernel ModulesDemodex kernel rootkit
Defense EvasionT1014 RootkitKernel-mode stealth
Defense EvasionT1562.001 Disable Security ToolsSecurity product evasion
Lateral MovementT1210 Exploitation of Remote ServicesNetwork exploitation
C2T1573.001 Encrypted ChannelEncrypted C2

Notable Campaigns

GhostEmperor APT has been linked to multiple significant campaigns targeting telecom, government in Southeast Asia and Middle East organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against GhostEmperor APT

Mjolnir Security provides specialized capabilities to detect and respond to GhostEmperor APT operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for GhostEmperor APT TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of GhostEmperor APT campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 18, 2026