logo

Notorious Chinese Hacker Gang GhostEmperor Re-Emerges After 2 Years

ID: c73b02b4-d80a-5212-874e-63f90aefe869

STIX ID: report--c73b02b4-d80a-5212-874e-63f90aefe869

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-07-19

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

Sygnia reported the return of GhostEmperor, a sophisticated Chinese-linked threat actor, using an updated Demodex kernel rootkit and improved evasion and infection techniques (including a reflective loader, obfuscation, and WMI-based command execution) to compromise networks and pivot to additional victims; the activity represents the group's first confirmed operations since 2021 and continues its targeting of telecommunications, government, and other high-value entities across multiple regions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.