Threat intelligence
- Suspected origin
- China
- First seen
- 2022-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Defense, Education, Financial, Government, Healthcare, Hospitality, IT, Manufacturing, Media, NGOs, Retail, Shipping and Logistics, Telecommunications
- TLP
- WHITE
(Trend Micro) Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa. The threat actor exploits public-facing servers and sends spear phishing emails to deliver previously unseen backdoors.
Our research allowed us to identify the campaign’s multiple connections with a China-nexus threat actor we track as Earth Lusca. However, since the campaign employs independent infrastructure and unique backdoors, we believe it to be a separate intrusion set that we named Earth Krahang.
Coverage 1
threat-intel
This report details a surge in cyber espionage activities targeting Latin American nations, primarily driven by China-linked Advanced Persistent Threat (APT) groups. These groups, including FamousSparrow and NegativeGlim…
