Demodex is a Windows kernel-mode rootkit used in cyber-espionage intrusions attributed to the Chinese-nexus GhostEmperor activity cluster, which is also associated in some reporting with Earth Estries/Salt Typhoon. It has targeted telecommunications providers, government entities, and related service-provider environments, particularly in Southeast Asia, with broader activity affecting other regions. Demodex provides stealth and persistence by concealing malware-associated files, services, registry artifacts, and network connections. It uses kernel-level hooking and anti-forensic measures, including techniques intended to obscure registry callback origins and evade forensic inspection. Observed deployment chains use multistage loaders, in-memory execution, reflective loading, encrypted configuration and shellcode, and obfuscation to reduce endpoint detection and impede sandbox analysis. Installations have abused a signed vulnerable driver to bypass Windows Driver Signature Enforcement and load the unsigned rootkit. Demodex has been deployed following compromise of public-facing servers and through remote execution in already compromised environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
8 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
GhostEmperor updated their Demodex rootkit to evade Endpoint Detection & Response (EDR) detection, impede sandbox analysis, and use a reflective loader to run in memory.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
CVE-2022-3236 A code injection vulnerability in the User Portal and Webadmin of Sophos Firewall allows for remote code execution.
We have observed them exploiting server-based N-day vulnerabilities, including the following: Ivanti Connect Secure VPN Exploitation (CVE-2023-46805 and CVE-2024-21887) A chain of exploits to bypass authentication, craft malicious requests, and execute arbitrary commands with elevated privileges.
We have observed them exploiting server-based N-day vulnerabilities, including the following: CVE-2023-48788 Fortinet FortiClient EMS SQL Injection Vulnerability
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers. | We found that they implanted the DEMODEX rootkit on vendor machines.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers. | We found that they implanted the DEMODEX rootkit on vendor machines.
ProxyLogon (CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) A set of four chained vulnerabilities that perform remote code execution (RCE) in Microsoft Exchange servers. | We found that they implanted the DEMODEX rootkit on vendor machines.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
An updated DEMODEX rootkit was observed where the attacker replaced the first-stage PowerShell script with a CAB file containing the necessary registry data, including the encrypted configuration and shellcode payload.
20 distinct techniques documented for this family, organized by ATT&CK tactic.
They execute a multi-stage infection chain ... to deploy encrypted payloads, such as DEMODEX rootkit. An updated DEMODEX rootkit was observed.
Encrypted configurations and shellcode are stored in registry keys, while reflective loaders decrypt and execute these components in memory, evading detection.
A Powershell script ... creates a malicious service DLL that masquerades a legitimate Windows system process to avoid detection.
Once the installation is complete, the CAB file is deleted, to hinder forensics.
35 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A rootkit used by Earth Estries for stealth and persistence, including on vendor machines and long-term targets. The report describes multi-stage installation, anti-analysis via control flow flattening, and newer CAB-bundled deployment variants.
Kernel-mode rootkit deployed by Salt Typhoon on servers as part of its server-side toolset.
Rootkit referenced as an additional payload deployed by SnappyBee in the described campaigns.
Rootkit referenced as an additional payload deployed by SnappyBee in the described campaigns.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.