SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

GhostEmperor

🏛️ Nation-StateLast active: 2026-09-25First seen: 2025-02-24G1045 ↗
3
linked CVEs
Also known as
FamousSparrowUNC2286Salt TyphoonRedMikeOPERATOR PANDA
Targeted industries
Government
GhostEmperor is a Chinese-speaking threat actor that targets government entities and telecom companies in Southeast Asia. They employ a Windows kernel-mode rootkit called Demodex to gain remote control over their targeted servers. The actor demonstrates a high level of sophistication and uses various anti-forensic and anti-analysis techniques to evade detection. They have been active for a significant period of time and continue to pose a threat to their targets.
Source: misp_galaxy · Collected: 2026-09-25
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-48842
suspected

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

CVSS 8.1
CVE-2026-87902
suspected

An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.php` file outside the active theme directories. If relevant pre-conditions for both the server and the active theme are met, this can lead to RCE.

CVSS 8.1
KEV
CVE-2026-42542
suspected

TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process by sending a single crafted RPC packet. No credentials or prior session state are required. Version 3.4.1.6 fixes the issue.

CVSS 7.5
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
MITRE ATT&CK Techniques Used14 techniques
Across 12 tactics
🛰️ Infrastructure & IOCs49
domainthird-party.com—2026-09-25
ip38.60.224.235—2026-09-18
ip27.102.113.240—2026-09-18
sha176c430b55f180a85f4e1a1e40e4a2ea37db97599—2026-09-18
sha1cc350ba25947b7f9ec5d11ea8269407c0fd74095—2026-09-18
sha1e2b0851e2e281cc7bca3d6d9b2fa0c4b7ac5a02b—2026-09-18
ip38.60.241.127—2026-09-18
sha1bb2f5b573ac7a761015daad0b7ff03b294dc60f6—2026-09-18
sha1ebc93a546bcdf6cc1eb61d7174bcb85407bbd892—2026-09-18
ip149.104.90.203—2026-09-18
sha10dc20b2f11118d5c0cc46b082d7f5dc060276157—2026-09-18
sha1c36ecd2e0f38294e1290f4b9b36f602167e33614—2026-09-18
sha15265e8edc9b5f7dd00fc772522511b8f3be217e3—2026-09-18
sha17d66b550ea68a86fcc0958e7c159531d4431b788—2026-09-18
sha1b9601e60f87545441bf8579b2f62668c56507f4a—2026-09-18
sha1f35ce62abeedfb8c6a38ceac50a250f48c41e65e—2026-09-18
sha11b06e877c2c12d74336e7532bc0ecf761e5fa5d4—2026-09-18
sha1d03fd329627a58b40e805f4f55b5d821063ac27f—2026-09-18
sha1a91b42e5062fef608f285002debaff9358162b25—2026-09-18
sha144f0a22b143b79fa760bf31e14c8fff714c8a2a1—2026-09-18
sha123e228d5603b4802398b2e7419187aef71ff9dd5—2026-09-18
ip38.54.57.17—2026-09-18
sha14df896624695ea2780552e9ea3c40661dc84efc8—2026-09-18
ip38.60.209.106—2026-09-18
ip103.85.25.166—2026-09-18
sha1aa823148eea6f43d8eb9bf20412402a7739d91c2—2026-09-18
sha15f1553f3af9425ef5d68341e991b6c5ec96a82eb—2026-09-18
domaincredits.offices-analytics.com—2026-09-18
md5922c1edb47fba94b548edca863165fb1—2026-09-18
ip130.94.101.82—2026-09-18
sha1fdc44057e87d7c350e6df84bb72541236a770ba2—2026-09-18
ip38.60.224.51—2026-09-18
sha15df3c882db6be14887182b7439b72a86bd28b83f—2026-09-18
sha1ef189737fb7d61b110b9293e8838526dce920127—2026-09-18
sha1db1591c6e23160a94f6312ca46da2d0bb243322c—2026-09-18
sha10925f24082971f50edd987d82f708845a6a9d7c9—2026-09-18
domainamelicen.com—2026-09-18
sha12560b7e28b322bb7a56d0b1da1b2652e1efe76ea—2026-09-18
ip38.60.241.65—2026-09-18
sha256e0b6f8535e19f0a4938e3317de0c4493ecea17aa906fd0454805ba2086cbf3a8—2026-09-18
ip45.131.179.24—2026-09-18
sha13a395daaf518be113fcff2e5e48acd9b9c0de69d—2026-09-18
ip38.60.241.193—2026-09-18
ip43.254.216.195—2026-09-18
sha1873f98caf234c3a8a9db18343dad7b42117e85d4—2026-09-18
ip38.60.197.55—2026-09-18
sha1c26f04790c6fb7950d89ab1b08207ace01efb536—2026-09-18
ip149.104.87.228—2026-09-18
sha1d6d32a1f17d48fe695c0778018c0d51626db4a3b—2026-09-18
📰 Threat Intel Coverage7
Digest reports mentioning this actor (incl. aliases)
CISA urges critical infrastructure to operate in isolation during conflictsmatched as Salt Typhoon2026-05-08
Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implantmatched as Salt Typhoon2025-12-12
Ongoing Exploitation of Cisco IOS XE Vulnerability with BadCandy Implantmatched as Salt Typhoon2025-11-08
Chinese Hackers Breach US Telecoms via Unpatched Cisco Routersmatched as FamousSparrow2025-02-14
Chinese Hackers Breach US Telecoms via Unpatched Cisco Routersmatched as RedMike2025-02-14
Chinese Hackers Breach US Telecoms via Unpatched Cisco Routersmatched as Salt Typhoon2025-02-14
Chinese Hackers Breach US Telecoms via Unpatched Cisco Routersmatched as UNC22862025-02-14