Description
GhostEmperor is an implant toolset associated with a Chinese speaking threat actor that targets high profile victims with kernel mode rootkit functionality. Kaspersky documented the group's infection chain and post exploitation toolset in 2021, and Sygnia reported the return of its Demodex tooling in 2024.
Stats
- First seen
- March 2022
- Last seen
- October 2026
Alert name variants
| Alert Name |
|---|
| ByteCode-MSIL.Trojan.GhostEmperor |
| Script-PowerShell.Downloader.GhostEmperor |
| Win64.Trojan.GhostEmperor |