216.73.216.6

The Return of Ghost Emperor’s Demodex

· Published 08/08/2024 11:12 · Modified 08/08/2024 11:38

Export JSON

Essential information

Published
08/08/2024 11:12
Modified
08/08/2024 11:38
Tags
2024-08-08 demodex ghost emperor rootkit
Related entities
1 vulnerabilities (cve), 3 observables, 1 intrusion sets (apt), 13 techniques (mitre), 1 malware

Description

This document examines a recent infection chain utilized by the sophisticated China-nexus threat group GhostEmperor. It delves into the multi-stage loading process of the , which incorporates several obfuscation techniques and loading schemes. The analysis covers various components, including a batch file, PowerShell script, and malicious service DLL, which ultimately loads a reflective loader and the core implant. The core implant handles command-and-control communication and installs the kernel , leveraging Cheat Engine's signed driver to bypass driver signature enforcement.

External references