Notorious Chinese Hacker Gang GhostEmperor Re-Emerges After 2 Years
ID: c73b02b4-d80a-5212-874e-63f90aefe869
STIX ID: report--c73b02b4-d80a-5212-874e-63f90aefe869
Feed Name: Dark Reading
Sygnia reported the return of GhostEmperor, a sophisticated Chinese-linked threat actor, using an updated Demodex kernel rootkit and improved evasion and infection techniques (including a reflective loader, obfuscation, and WMI-based command execution) to compromise networks and pivot to additional victims; the activity represents the group's first confirmed operations since 2021 and continues its targeting of telecommunications, government, and other high-value entities across multiple regions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
