{"id":3483,"date":"2021-08-13T22:10:52","date_gmt":"2021-08-14T03:10:52","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3483"},"modified":"2021-08-13T22:10:54","modified_gmt":"2021-08-14T03:10:54","slug":"ghostemperor-group-that-targets-high-profile-users","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/","title":{"rendered":"GhostEmperor group that targets high profile users"},"content":{"rendered":"\n<p>As we well know, cyber threat campaigns do not stop and today we will see one that is in full swing, this threat takes advantage of Microsoft Exchange vulnerabilities to target high-profile victims with a set of advanced tools. Besides this according to Kaspersky this campaign did not have any similarities with any known threat actor until now but&#8230; Apparently GhostEmperor is a Chinese speaking threat actor which has mainly focused on targets in Southeast Asia.<\/p>\n\n\n\n<p>GhostEmperor seems to know what it does, and it also stands out because it uses a previously unknown Windows kernel mode rootkit. Rootkits provide remote control access to the servers they target. Acting covertly, they are well known for hiding from researchers and security solutions and thus managing to avoid the Windows driver signature enforcement mechanism, GhostEmperor uses a loading scheme that involves a component of a code project open called &#8220;Cheat Engine&#8221;.<\/p>\n\n\n\n<p>According to Kaspersky, GhostEmperor is a clear example of how cybercriminals are looking for new techniques to use and new vulnerabilities to exploit. And it is not surprising, we have seen many threats arise out of nowhere and now with Microsoft Exchange vulnerabilities many cybercriminal groups take advantage of these vulnerabilities since this is not the only threat that has attacked Microsoft Exchange vulnerabilities. This threat undoubtedly brought new problems to the already well-established trend of attacks against Microsoft Exchange servers.<\/p>\n\n\n\n<p>The best we can do to avoid these threats is to prepare and stay informed, especially with the recent growth of vulnerabilities and attacks on Microsoft Exchange.<\/p>\n\n\n\n<p>Other reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/strongpity-an-infamous-group-of-cybercriminals\/\">StrongPity infamous group of cybercriminals<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/group-nso-a-controversial-company\/\">Group NSO \u2013 A controversial company<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we well know, cyber threat campaigns do not stop and today we will see one that is in full swing, this threat takes advantage of Microsoft Exchange vulnerabilities to target high-profile victims with a set of advanced tools. Besides this according to Kaspersky this campaign did not have any similarities with any known threat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3484,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3483","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>GhostEmperor group that targets high profile users - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GhostEmperor group that targets high profile users - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-08-14T03:10:52+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-08-14T03:10:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"580\" \/>\n\t<meta property=\"og:image:height\" content=\"387\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"GhostEmperor group that targets high profile users\",\"datePublished\":\"2021-08-14T03:10:52+00:00\",\"dateModified\":\"2021-08-14T03:10:54+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/\"},\"wordCount\":276,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/GhostEmperor.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/\",\"name\":\"GhostEmperor group that targets high profile users - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/GhostEmperor.jpg\",\"datePublished\":\"2021-08-14T03:10:52+00:00\",\"dateModified\":\"2021-08-14T03:10:54+00:00\",\"description\":\"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/GhostEmperor.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/08\\\/GhostEmperor.jpg\",\"width\":580,\"height\":387},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/ghostemperor-group-that-targets-high-profile-users\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GhostEmperor group that targets high profile users\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"GhostEmperor group that targets high profile users - Truxgo Server Blog","description":"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/","og_locale":"es_MX","og_type":"article","og_title":"GhostEmperor group that targets high profile users - Truxgo Server Blog","og_description":"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....","og_url":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-08-14T03:10:52+00:00","article_modified_time":"2021-08-14T03:10:54+00:00","og_image":[{"width":580,"height":387,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"GhostEmperor group that targets high profile users","datePublished":"2021-08-14T03:10:52+00:00","dateModified":"2021-08-14T03:10:54+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/"},"wordCount":276,"commentCount":1,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/","url":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/","name":"GhostEmperor group that targets high profile users - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg","datePublished":"2021-08-14T03:10:52+00:00","dateModified":"2021-08-14T03:10:54+00:00","description":"As we have seen, cybercriminals are taking advantage of vulnerabilities in Microsoft Exchange and GhostEmperor is no the exception.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/08\/GhostEmperor.jpg","width":580,"height":387},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/ghostemperor-group-that-targets-high-profile-users\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"GhostEmperor group that targets high profile users"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3483","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3483"}],"version-history":[{"count":3,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3483\/revisions"}],"predecessor-version":[{"id":3549,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3483\/revisions\/3549"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3484"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3483"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3483"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3483"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}