Netskope Threat Labs

GhostEmperor

ATP Sandbox Adv. Heuristics

GhostEmperor is an implant toolset associated with a Chinese speaking threat actor that targets high profile victims with kernel mode rootkit functionality. Kaspersky documented the group's infection chain and post exploitation toolset in 2021, and Sygnia reported the return of its Demodex tooling in 2024.

First seen
March 2022
Last seen
October 2026
Alert Name
ByteCode-MSIL.Trojan.GhostEmperor
Script-PowerShell.Downloader.GhostEmperor
Win64.Trojan.GhostEmperor