news.mlab.sh
Threat intelligence
Threat actor

Earth Krahang

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
China
First seen
2022-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Defense, Education, Financial, Government, Healthcare, Hospitality, IT, Manufacturing, Media, NGOs, Retail, Shipping and Logistics, Telecommunications
TLP
WHITE

(Trend Micro) Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa. The threat actor exploits public-facing servers and sends spear phishing emails to deliver previously unseen backdoors. Our research allowed us to identify the campaign’s multiple connections with a China-nexus threat actor we track as Earth Lusca. However, since the campaign employs independent infrastructure and unique backdoors, we believe it to be a separate intrusion set that we named Earth Krahang.

Coverage 1