GhostEmperor is an advanced persistent threat malware framework/campaign associated with a Chinese-speaking threat actor and reported overlap with Lucky Mouse. It targeted government and telecommunications entities, primarily in Southeast Asia, with additional victims noted in Egypt, Afghanistan, and Ethiopia. Initial access was obtained through exploitation of public-facing servers, including Apache, IIS, Oracle, and Microsoft Exchange systems; the campaign is specifically noted as exploiting ProxyLogon shortly after disclosure. The intrusion set used a sophisticated multi-stage infection chain involving PowerShell droppers, service DLLs, in-memory implants, and in some cases DLL side-loading via legitimate Microsoft utilities. A central component is Demodex, a previously unknown Windows kernel-mode rootkit loaded by abusing the signed dbk64.sys driver from Cheat Engine to bypass Windows Driver Signature Enforcement. Demodex supports Windows 10 and hides files, registry keys, services, and TCP connections, including by hooking the nsiproxy.sys IOCTL dispatcher; it also used a patched pci.sys driver section to mask registry callback origins and employed anti-forensic measures to evade tools such as WinDbg and Volatility. The malware framework provided remote desktop capability, console access, and full filesystem control. Command-and-control traffic used a customized Malleable C2 profile and was disguised as RIFF, JPEG, or PNG files to blend with benign traffic. Post-exploitation activity included use of legitimate and open-source tools such as PsExec, ProcDump, WinRAR, mimkat_ssp, and Ladon, with some Demodex deployments performed remotely via WMI or PsExec. Reported infrastructure included domains such as newlylab[.]com and reclubpress[.]com and IP space in Hong Kong and South Korea. The malware used extensive obfuscation, including string and API obfuscation, control-flow flattening, PE header removal, and unique obfuscation stubs per build. Technical similarities to the Derusbi rootkit and use of Netbot were also noted. The campaign was active as early as July 2020 and demonstrated the ability to remain undetected for months.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named malware/tool or cluster referenced with several aliases, but no behavioral details are provided.
GhostEmperor is a sophisticated multi-stage malware framework used by a Chinese-speaking APT group. It provides remote control over compromised servers, featuring a custom in-memory implant, advanced anti-forensic and anti-analysis techniques, and the ability to deploy a Windows kernel mode rootkit (Demodex) for stealth. The framework is capable of remote desktop control, file system manipulation, arbitrary code execution, and C2 communication using malleable profiles and fake file headers. It is primarily used for long-term espionage and persistence in high-profile targets.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.