2 August 2021

New Chinese-speaking cyberespionage group targets high-profile victims in Southeast Asia


New Chinese-speaking cyberespionage group targets high-profile victims in Southeast Asia

Security researchers at Kaspersky discovered a previously undocumented cyberespionage campaign that uses vulnerabilities in Microsoft Exchange email software in attacks targeting high-profile victims in Southeast Asia, including government entities and telecom companies.

Dubbed GhostEmperor, the Chinese-speaking threat actor has been observed using a never-before-seen Windows kernel-mode rootkit that provides remote access to target servers.

GhostEmperor leverages a loading scheme involving a component of an open-source project named “Cheat Engine,” which allows them to bypass the Windows Driver Signature Enforcement mechanism. This advanced toolset, which has been in use since at least July 200, is unique, Kaspersky says, and bears no similarity to already known threat actors.

“As detection and protection techniques evolve, so do APT actors,” said David Emm, security expert at Kaspersky. “They typically refresh and update their toolsets. GhostEmperor is a clear example of how cybercriminals look for new techniques to use and new vulnerabilities to exploit. Using a previously unknown, sophisticated rootkit, they brought new problems to the already well-established trend of attacks against Microsoft Exchange servers.”


Back to the list

Latest Posts

China-linked LightSpy iOS implant re-emerges, targets South Asia

China-linked LightSpy iOS implant re-emerges, targets South Asia

LightSpy contains modules designed to exfiltrate device information and saved files.
16 April 2024
Cryptojacker indicted for defrauding cloud service providers of $3.5M

Cryptojacker indicted for defrauding cloud service providers of $3.5M

Parks allegedly manipulated the cloud providers into granting him elevated privileges and benefits.
16 April 2024
Firebird RAT developers and sellers arrested in the US and Australia

Firebird RAT developers and sellers arrested in the US and Australia

The malware allows to remotely access victims' computers and perform illicit activities.
16 April 2024