Chinese-Linked Threat Actor ‘Ghost Emperor’ Returns With Demodex Rootkit
ID: ca8c6197-4b5a-5902-87e1-4caa53d45a04
STIX ID: report--ca8c6197-4b5a-5902-87e1-4caa53d45a04
Feed Name: The Cyber Express
Researchers from Sygnia report that China-linked Ghost Emperor resurfaced with an updated Demodex rootkit targeting Southeast Asian telecom and government entities. The multi-stage infection chain uses WMIExec to drop a CAB, imports malicious registry keys, runs an encrypted PowerShell to create a fake Windows service (WdiSystem) that loads a malicious Service DLL (prints1m.dll), and employs advanced evasion (process mitigation to block non-Microsoft DLLs, dynamic function loading, encrypted configuration, and a reflective loader); IOCs were published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
