APT PRC State-Sponsored Active since 2020

GhostEmperor

Advanced kernel-level rootkit (Demodex). Targets telecom, government in Southeast Asia.

Scroll

GhostEmperor is a PRC state-sponsored threat group known for deploying the Demodex kernel-level rootkit — one of the most sophisticated rootkits observed in the wild. The group targets telecom providers, government agencies, and high-value entities primarily in Southeast Asia and the Middle East, with a focus on maintaining long-term persistent access.

AttributeDetail
NamesGhostEmperor / FamousSparrow
AttributionPRC State-Sponsored
Active Since2020
Primary FocusAdvanced kernel-level rootkit (Demodex). Targets telecom, government in Southeast Asia.

Overview

GhostEmperor is a PRC state-sponsored threat group known for deploying the Demodex kernel-level rootkit — one of the most sophisticated rootkits observed in the wild. The group targets telecom providers, government agencies, and high-value entities primarily in Southeast Asia and the Middle East, with a focus on maintaining long-term persistent access.

Attribution

GhostEmperor / FamousSparrow is attributed to PRC State-Sponsored, active since at least 2020. Advanced kernel-level rootkit (Demodex). Targets telecom, government in Southeast Asia.

Notable Campaigns

MITRE ATT&CK Mapping

Technique IDTechniqueConfidence
T1014RootkitHigh
T1059Command and Scripting InterpreterHigh
T1071Application Layer ProtocolHigh
T1005Data from Local SystemHigh
T1190Exploit Public-Facing ApplicationHigh

Detection & Defense

Recommended Defenses

Monitor for the TTPs listed above using your SIEM and EDR platforms. Prioritize patching of internet-facing applications and enforce MFA on all remote access. Mjolnir Security provides continuous threat hunting and monitoring for GhostEmperor activity patterns.

Mjolnir Security — Threat Intelligence & Response

Mjolnir Security provides 24/7 threat monitoring, incident response, and threat intelligence services. Contact us for threat hunting specifically targeting GhostEmperor TTPs in your environment.

Threat Hunting Incident Response Threat Intelligence SOC-as-a-Service

mjolnirsecurity.com — 24/7 Incident Response Hotline: +1 833 403 5875