Threadlinqs IntelligenceStart free

Threat actorChinaTracked since 2026-03

GhostEmperor

Also known as:FamousSparrowOPERATOR PANDARedMikeSalt TyphoonUNC2286Earth EstriesUAT-9244Salt Typhoon-adjacent ecosystemGhostEmperor-related ecosystemGhostEmperor-adjacent

As of 2026-08-24, GhostEmperor is a China-nexus threat actor tracked by Threadlinqs Intelligence across 5 threats spanning malware, apt. Also known as FamousSparrow, OPERATOR PANDA, RedMike, Salt Typhoon. ATT&CK coverage spans 53 techniques across 14 tactics in 5 of 5 tracked threats. Most-observed techniques: T1071.001 (Web Protocols), T1140 (Deobfuscate/Decode Files or Information), T1190 (Exploit Public-Facing Application).

Tracked threats
53 critical · 1 high · 1 medium
First seen
2026-03-07
Last seen
2026-08-24
ATT&CK techniques
53across 5 of 5 threats
Related CVEs
5Referenced by its activity
Attribution
ChinaNation or origin
Nation: China · 5 tracked threat(s) · Categories: MALWARE, APT

Activity timeline

GhostEmperor appears in 5 tracked threats between and ; the busiest month was 2026-08 with 2 reports.

ATT&CK techniques observed

53 techniques observed across 5 of 5 tracked threats · Stealth (formerly Defense Evasion) (15), Command and Control (7), Execution (5), Persistence (5), Discovery (4), Resource Development (4)
  • T1071.001 Web Protocols — Command and Controlobserved in 5 of 5 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
  • T1190 Exploit Public-Facing Application — Initial Accessobserved in 5 of 5 tracked threats
  • T1574.001 DLL — Stealth (formerly Defense Evasion)observed in 5 of 5 tracked threats
  • T1014 Rootkit — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 4 of 5 tracked threats
  • T1082 System Information Discovery — Discoveryobserved in 4 of 5 tracked threats
  • T1505.003 Web Shell — Persistenceobserved in 4 of 5 tracked threats
  • T1543.003 Create or Modify System Process: Windows Service — Persistenceobserved in 4 of 5 tracked threats
  • T1021.001 Remote Desktop Protocol — Lateral Movementobserved in 3 of 5 tracked threats
  • T1021.002 SMB/Windows Admin Shares — Lateral Movementobserved in 3 of 5 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats
  • T1059.001 PowerShell — Executionobserved in 3 of 5 tracked threats
  • T1070.004 File Deletion — Stealth (formerly Defense Evasion)observed in 3 of 5 tracked threats

Tracked threats

Related CVEs

5 CVEs referenced by tracked GhostEmperor activity