SYMBOLCOMMON_NAMEaka. SYNONYMS

GhostEmperor  (Back to overview)

aka: FamousSparrow, OPERATOR PANDA, RedMike, Salt Typhoon, UNC2286

GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.


Associated Families
win.sparrow_door

References
2026-09-17 ⋅ ESET Research ⋅ Alexandre Côté Cyr, Romain Dumont
Beware the SparroWock: The backdoor that bites, the commands that catch
SparrowDoor
2025-02-13 ⋅ Recorded Future ⋅ Insikt Group
RedMike (Salt Typhoon) Exploits Vulnerable Cisco Devices of Global Telecommunications Providers
GhostEmperor
2025-01-21 ⋅ Trend Micro ⋅ Leon Chang, Theo Chen
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
Cobalt Strike HemiGate ShadowPad SNAPPYBEE SparrowDoor UNC4841
2024-09-26 ⋅ The Wall Street Journal ⋅ Dustin Volz, Robert McMillan, Sarah Krouse
China-Linked Hackers Breach U.S. Internet Providers in New ‘Salt Typhoon’ Cyberattack
GhostEmperor
2024-07-17 ⋅ SYGNIA ⋅ Dor Nizar
The Return of Ghost Emperor’s Demodex
GhostEmperor GhostEmperor
2023-10-06 ⋅ ITOCHU ⋅ ITOCHU Cyber & Intelligence Inc.
Sequel: Gifts from Tropical Pirates - Who is the Sender? Look for the Attacker Group
EntryShell SparrowDoor
2023-10-05 ⋅ VirusBulletin ⋅ Hajime Yanagishita, Suguru Ishimaru, Yusuke Niwa
Unveiling activities of Tropic Trooper 2023: deep analysis of Xiangoop Loader and EntryShell payload
EntryShell SparrowDoor Xiangoop
2023-08-29 ⋅ Google ⋅ Austin Larsen, John Palmisano, John Wolfram, Mathew Potaczek, Michael Raggi
Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)
GhostEmperor UNC4841
2023-08-29 ⋅ Mandiant ⋅ Austin Larsen, John Palmisano, John Wolfram, Mathew Potaczek, Michael Raggi
Diving Deep into UNC4841 Operations Following Barracuda ESG Zero-Day Remediation (CVE-2023-2868)
GhostEmperor
2022-02-28 ⋅ NCSC UK ⋅ NCSC UK
Malware Analysis Report: SparrowDoor
SparrowDoor GhostEmperor
2021-09-30 ⋅ Kaspersky Labs ⋅ Kaspersky Labs
GhostEmperor’s infection chain and post-exploitation toolset: technical detail
GhostEmperor GhostEmperor
2021-09-30 ⋅ Kaspersky ⋅ Aseel Kayal, Mark Lechtik, Paul Rascagnères, Vasily Berdnikov
GhostEmperor: From ProxyLogon to kernel mode
GhostEmperor GhostEmperor
2021-09-23 ⋅ ESET Research ⋅ Matthieu Faou, Tahseen Bin Taj
FamousSparrow: A suspicious hotel guest
SparrowDoor GhostEmperor

Credits: MISP Project