logo

Chinese-Linked Threat Actor ‘Ghost Emperor’ Returns With Demodex Rootkit

ID: ca8c6197-4b5a-5902-87e1-4caa53d45a04

STIX ID: report--ca8c6197-4b5a-5902-87e1-4caa53d45a04

Feed Name: The Cyber Express

Threat Score
85/100

Date Published: 2024-07-20

Date Updated: 2026-04-23

Author: Alan J

...
...

Researchers from Sygnia report that China-linked Ghost Emperor resurfaced with an updated Demodex rootkit targeting Southeast Asian telecom and government entities. The multi-stage infection chain uses WMIExec to drop a CAB, imports malicious registry keys, runs an encrypted PowerShell to create a fake Windows service (WdiSystem) that loads a malicious Service DLL (prints1m.dll), and employs advanced evasion (process mitigation to block non-Microsoft DLLs, dynamic function loading, encrypted configuration, and a reflective loader); IOCs were published.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.