Skip to content
May 15, 2025
  • Facebook
  • Instagram
  • Twitter
  • Youtube
DFRAC_ORG

DFRAC_ORG

Digital Forensics, Research and Analytics Center

Primary Menu
  • Home
  • Generative AI
  • Fact Check
    • Election
    • Health
    • Conflict Zone
  • Hate Monitor
  • Opinion
  • Hashtag Scanner
  • News
  • Podcasts
  • About
    • About Us
    • Contact us
    • Our Team
    • Non-Partisanship Policy
    • Privacy Policy
    • Resources
    • Collaborations
  • हिन्दी
  • English
  • اردو
Donate us
  • Featured
  • Online Fraud
  • Opinion

Chinese espionage group targets newfound weaknesses in Exchange, targets giant companies in South-East Asia

DFRAC Editor October 13, 2021
feature (3)

At the Security Analyst Summit that took place on September 30,2021, during which the security company Kaspersky Lab released a report on a new cyber espionage group called GhostEmperor who have been using new techniques to launch cyberattacks on servers. 

The main target of GhostEmperor is government and telecommunications services in Malaysia, Thailand, Indonesia even spanning all the way to Afghanistan and Egypt. 

It is being said that the group is focused on gaining long term access to its victims and uses a highly sophisticated toolkit that is even compatible with Windows 10 further increasing the risks. 

GhostEmperor entered servers through applications such as Oracle and Microsoft Exchange whose servers were exploited by the group to enter the target servers. 

In the report, they have detailed how GhostEmperor uses different scripts and tools to help infiltrate the network’s backdoors. 

The architecture used by the attackers to stage shellcode buffers in the winlogon.exe process in order to handle various remote control features
Courtesy: Kaspersky

After infiltrating the network, the backdoor is used to install the open-source Cheat Engine which is primarily used by gamers to install cheat codes to their games. This was then used to install a very powerful rootkit called Demodex to their server. 

The toolkit is developed in such a manner that it continues to stay on the system even after the operating system is reinstalled and updated to Windows 10. 

The main reason why this group sticks out is because the group seems to be using anti-forensics and anti-analysis tools that caused a hindrance to security researchers who were trying to analyse their malware.

They also packaged fake data and sent it to the command rather than sending the real things. This kind of sophistication that GhostEmperor displays is something to keep your eye on. 

Share this…
  • Facebook
  • Twitter
  • Pinterest
  • Whatsapp

Continue Reading

Previous: Fact Check: Images from an Indian drama being used to show detention of PLA soldiers by the Indian Army
Next: Fact-Check: PM Modi declared ‘Chief President’ amongst 53 world leaders?

Related Stories

Fact Check: Pakistani users spread a deepfake video of Colonel Sofia Qureshi with fake claim
  • Fact Check
  • Fake
  • Featured

Fact Check: Pakistani users spread a deepfake video of Colonel Sofia Qureshi with fake claim

Nisar Ahmed Siddiqui May 15, 2025
Fake nuclear leak
  • Fact Check
  • Fake
  • Featured

Fake News of Nuclear Warhead explosion and radiation leak at Beas BrahMos Depot shared

Aayushi Rana May 15, 2025
al jazeera fake news
  • Fact Check
  • Featured
  • Misleading-en

Fake News: Al Jazeera Shares Unverified Claim About Capture of Indian Pilot

Aayushi Rana May 14, 2025

fact check

Fact Check: Pakistani users spread a deepfake video of Colonel Sofia Qureshi with fake claim Fact Check: Pakistani users spread a deepfake video of Colonel Sofia Qureshi with fake claim

Fact Check: Pakistani users spread a deepfake video of Colonel Sofia Qureshi with fake claim

May 15, 2025
Fake News of Nuclear Warhead explosion and radiation leak at Beas BrahMos Depot shared Fake nuclear leak

Fake News of Nuclear Warhead explosion and radiation leak at Beas BrahMos Depot shared

May 15, 2025
Fake News: Al Jazeera Shares Unverified Claim About Capture of Indian Pilot al jazeera fake news

Fake News: Al Jazeera Shares Unverified Claim About Capture of Indian Pilot

May 14, 2025
False Claim of Indian Army Confirming the Loss of Rafale Jet in a Press Briefing shared Rafael jet crash

False Claim of Indian Army Confirming the Loss of Rafale Jet in a Press Briefing shared

May 13, 2025
Fact Check: Video of Anti-India Protest Shared as From Tamil Nadu Is Misleading anti india protest

Fact Check: Video of Anti-India Protest Shared as From Tamil Nadu Is Misleading

May 13, 2025
Fact Check: Digitally altered image falsely shows Greta Thunberg holding a book on Jews Fact Check (1) (1)

Fact Check: Digitally altered image falsely shows Greta Thunberg holding a book on Jews

May 13, 2025

Connect with Us

  • Facebook
  • Instagram
  • Twitter
  • Youtube

IFCN certified

Newsletter

  • About Us
  • Contact us
  • Terms and Conditions
  • Privacy Policy
  • Non-Partisanship Policy
  • Facebook
  • Instagram
  • Twitter
  • Youtube
Copyright © 2025 | All Rights Reserved | Developed by OppsWeb Solutions | MoreNews by AF themes.