China-Backed Earth Baku Expands Cyber Attacks to Europe, Middle East, and Africa

Share:

The China-backed threat actor known as Earth Baku has diversified its targeting footprint beyond the Indo-Pacific region to include Europe, the Middle East, and Africa starting in late 2022.

Newly targeted countries as part of the activity include Italy, Germany, the U.A.E., and Qatar, with suspected attacks also detected in Georgia and Romania. Governments, media and communications, telecoms, technology, healthcare, and education are some of the sectors singled out as part of the intrusion set.

“The group has updated its tools, tactics, and procedures (TTPs) in more recent campaigns, making use of public-facing applications such as IIS servers as entry points for attacks, after which they deploy sophisticated malware toolsets on the victim’s environment,” Trend Micro researchers Ted Lee and Theo Chen said in an analysis published last week.

The findings build upon recent reports from Zscaler and Google-owned Mandiant, which also detailed the threat actor’s use of malware families like DodgeBox (aka DUSTPAN) and MoonWalk (aka DUSTTRAP). Trend Micro has given them the monikers StealthReacher and SneakCross.

Earth Baku, a threat actor associated with APT41, is known for its use of StealthVector as far back as October 2020. Attack chains involve the exploitation of public-facing applications to drop the Godzilla web shell, which is then used to deliver follow-on payloads.

China-Backed Earth Baku

StealthReacher has been classified as an enhanced version of the StealthVector backdoor loader that’s responsible for launching SneakCross, a modular implant and a likely successor to ScrambleCross that leverages Google services for its command-and-control (C2) communication.

The attacks are also characterized by the use of other post-exploitation tools such as iox, Rakshasa, and a Virtual Private Network (VPN) service known as Tailscale. Exfiltration of sensitive data to the MEGA cloud storage service is accomplished by means of a command-line utility dubbed MEGAcmd.

“The group has employed new loaders such as StealthVector and StealthReacher, to stealthily launch backdoor components, and added SneakCross as their latest modular backdoor,” the researchers said.

“Earth Baku also used several tools during its post-exploitation including a customized iox tool, Rakshasa, TailScale for persistence, and MEGAcmd for efficient data exfiltration.”

Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:45 am, Jun 29, 2025
weather icon 22°C
L: 21° | H: 23°
broken clouds
Humidity: 72 %
Pressure: 1026 mb
Wind: 6 mph W
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 75%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:46 am
Sunset: 9:21 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 23°°C 0 mm 0% 5 mph 72 % 1026 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
20° | 35°°C 0 mm 0% 8 mph 71 % 1021 mb 0 mm/h
Tue Jul 01 10:00 pm
weather icon
22° | 33°°C 0 mm 0% 12 mph 70 % 1017 mb 0 mm/h
Wed Jul 02 10:00 pm
weather icon
16° | 22°°C 1 mm 100% 11 mph 94 % 1017 mb 0 mm/h
Thu Jul 03 10:00 pm
weather icon
14° | 20°°C 1 mm 100% 12 mph 95 % 1026 mb 0 mm/h
Today 10:00 am
weather icon
22° | 22°°C 0 mm 0% 5 mph 72 % 1026 mb 0 mm/h
Today 1:00 pm
weather icon
23° | 26°°C 0 mm 0% 5 mph 64 % 1026 mb 0 mm/h
Today 4:00 pm
weather icon
27° | 30°°C 0 mm 0% 3 mph 46 % 1024 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 4 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
weather icon
22° | 22°°C 0 mm 0% 3 mph 54 % 1021 mb 0 mm/h
Tomorrow 1:00 am
weather icon
21° | 21°°C 0 mm 0% 3 mph 65 % 1021 mb 0 mm/h
Tomorrow 4:00 am
weather icon
20° | 20°°C 0 mm 0% 4 mph 71 % 1020 mb 0 mm/h
Tomorrow 7:00 am
weather icon
22° | 22°°C 0 mm 0% 4 mph 62 % 1020 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,818.82
0.17%
Ethereum(ETH)
€2,084.32
0.74%
Tether(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
0.34%
Solana(SOL)
€128.42
2.67%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139978
0.67%
Shiba Inu(SHIB)
€0.000010
1.49%
Pepe(PEPE)
€0.000008
1.96%
Scroll to Top