news.mlab.sh
Threat intelligence
Threat actor

Salt Typhoon

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
Targeted countries
China
TLP
WHITE

(Kaspersky) GhostEmperor is a Chinese-speaking threat actor that has mostly focused on targets in Southeast Asia, including several government entities and telecom companies. The group stands out because it uses a formerly unknown Windows kernel-mode rootkit. Rootkits provide remote control access over the servers they target. Acting covertly, rootkits are notorious for hiding from investigators and security solutions. To bypass the Windows Driver Signature Enforcement mechanism, GhostEmperor uses a loading scheme involving a component of an open-source project named “Cheat Engine.” This advanced toolset is unique and Kaspersky researchers see no similarity to already known threat actors. Kaspersky experts have surmised that the toolset has been in use since at least July 2020.

Also known as

Earth EstriesFamousSparrowGhostEmperorOperator PandaRedMikeSalt TyphoonUNC2286

Vulnerabilities exploited

Tooling and malware

JumbledPath

MITRE ATT&CK techniques

T1572 Protocol TunnelingT1040 Network SniffingT1686 Disable or Modify System FirewallT1190 Exploit Public-Facing ApplicationT1136 Create Account

Coverage 7