A highly sophisticated Chinese-speaking threat actor targeting government and telecom sectors in Southeast Asia.
Analyst brief
GhostEmperor, also tracked as FamousSparrow or UNC2286, is a highly sophisticated, Chinese-speaking threat actor primarily targeting government entities and telecommunications companies in Southeast Asia. The actor leverages the Demodex kernel-mode rootkit for stealthy remote control and uses JumbledPath malware to conduct network reconnaissance. Their TTPs include exploiting public-facing applications for initial access, establishing persistence via SSH Authorized Keys, and using Protocol Tunneling for C2 to evade detection. Defenders should prioritize monitoring public-facing servers, auditing SSH key placements, and inspecting for anomalous network device configuration dumps.
GhostEmperor
FamousSparrowUNC2286Salt Typhoon
unknown
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.