Demodex is a Windows kernel-mode rootkit associated with Chinese cyber-espionage activity, most notably the GhostEmperor and Salt Typhoon intrusion clusters. It has been used in long-dwell operations against telecommunications providers, government entities, and related vendors, particularly in Asia and in telecom-focused espionage campaigns. Demodex is deployed after initial compromise as a stealth and persistence component on servers and vendor systems, where it supports continued attacker access while concealing malicious activity from defenders and forensic tooling.
A defining characteristic of Demodex is its kernel-level operation and driver-based stealth. Public reporting has described it as being loaded through abuse of a signed third-party driver to bypass Windows driver signature enforcement, enabling installation of an unsigned malicious driver. Once active, the rootkit hides attacker artifacts including files, services, registry objects, and network connections, and has been reported to hook kernel components to obscure malware-related TCP activity and mask callback origins. Demodex has also been described as incorporating obfuscation and anti-analysis measures, including techniques intended to frustrate memory forensics and reverse engineering.
Demodex appears as part of broader multi-stage post-compromise frameworks rather than as a standalone initial-access tool. It has been observed alongside backdoors such as GhostSpider and SnappyBee and with operator tooling including Cobalt Strike. In some intrusion chains, SnappyBee has been used to deploy the Demodex rootkit. Reporting also indicates remote deployment in already-compromised environments using administrative execution mechanisms. Its role is consistent with maintaining covert persistence, supporting post-exploitation, and enabling defense evasion during extended espionage operations.
Operationally, Demodex is notable because it reflects continued use of sophisticated rootkit tradecraft in modern state-linked intrusions. Its use against telecommunications environments and contractor networks indicates a focus on surveillance, durable access, and stealth within strategically important infrastructure.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
На серверах (за пределами сетевых устройств) Salt Typhoon разворачивает бэкдор GhostSpider (по данным Trend Micro, разработан специально для телеком-сетей), руткит Demodex (kernel-mode), Cobalt Strike, а также SnappyBee и HemiGate.
1 distinct technique documented for this family, organized by ATT&CK tactic.
13 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Kernel-mode rootkit deployed by Salt Typhoon on servers as part of its server-side toolset.
Rootkit referenced as an additional payload deployed by SnappyBee in the described campaigns.
Rootkit referenced as an additional payload deployed by SnappyBee in the described campaigns.
Rootkit referenced as an additional payload deployed in campaigns where SnappyBee is used post-compromise.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.