China-Backed Earth Baku Expands Cyber Attacks to Europe, Middle East, and Africa

Share:

The China-backed threat actor known as Earth Baku has diversified its targeting footprint beyond the Indo-Pacific region to include Europe, the Middle East, and Africa starting in late 2022.

Newly targeted countries as part of the activity include Italy, Germany, the U.A.E., and Qatar, with suspected attacks also detected in Georgia and Romania. Governments, media and communications, telecoms, technology, healthcare, and education are some of the sectors singled out as part of the intrusion set.

“The group has updated its tools, tactics, and procedures (TTPs) in more recent campaigns, making use of public-facing applications such as IIS servers as entry points for attacks, after which they deploy sophisticated malware toolsets on the victim’s environment,” Trend Micro researchers Ted Lee and Theo Chen said in an analysis published last week.

The findings build upon recent reports from Zscaler and Google-owned Mandiant, which also detailed the threat actor’s use of malware families like DodgeBox (aka DUSTPAN) and MoonWalk (aka DUSTTRAP). Trend Micro has given them the monikers StealthReacher and SneakCross.

Earth Baku, a threat actor associated with APT41, is known for its use of StealthVector as far back as October 2020. Attack chains involve the exploitation of public-facing applications to drop the Godzilla web shell, which is then used to deliver follow-on payloads.

China-Backed Earth Baku

StealthReacher has been classified as an enhanced version of the StealthVector backdoor loader that’s responsible for launching SneakCross, a modular implant and a likely successor to ScrambleCross that leverages Google services for its command-and-control (C2) communication.

The attacks are also characterized by the use of other post-exploitation tools such as iox, Rakshasa, and a Virtual Private Network (VPN) service known as Tailscale. Exfiltration of sensitive data to the MEGA cloud storage service is accomplished by means of a command-line utility dubbed MEGAcmd.

“The group has employed new loaders such as StealthVector and StealthReacher, to stealthily launch backdoor components, and added SneakCross as their latest modular backdoor,” the researchers said.

“Earth Baku also used several tools during its post-exploitation including a customized iox tool, Rakshasa, TailScale for persistence, and MEGAcmd for efficient data exfiltration.”

Ravie Lakshmanan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
2:04 am, Mar 11, 2025
weather icon 7°C
L: 6° | H: 8°
overcast clouds
Humidity: 80 %
Pressure: 1007 mb
Wind: 10 mph NNE
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 8 km
Sunrise: 6:23 am
Sunset: 5:57 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0.2 mm 20% 12 mph 80 % 1008 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 7°°C 1 mm 100% 11 mph 85 % 1007 mb 0 mm/h
Thu Mar 13 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 10 mph 88 % 1005 mb 0 mm/h
Fri Mar 14 9:00 pm
weather icon
1° | 8°°C 0.2 mm 20% 9 mph 88 % 1015 mb 0 mm/h
Sat Mar 15 9:00 pm
weather icon
2° | 8°°C 0 mm 0% 12 mph 66 % 1028 mb 0 mm/h
Today 3:00 am
weather icon
7° | 7°°C 0 mm 0% 11 mph 80 % 1007 mb 0 mm/h
Today 6:00 am
weather icon
6° | 7°°C 0 mm 0% 11 mph 76 % 1007 mb 0 mm/h
Today 9:00 am
weather icon
6° | 7°°C 0 mm 0% 12 mph 69 % 1008 mb 0 mm/h
Today 12:00 pm
weather icon
9° | 9°°C 0 mm 0% 11 mph 46 % 1008 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 8°°C 0 mm 0% 12 mph 47 % 1007 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 0 mm 0% 7 mph 50 % 1007 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0.2 mm 20% 8 mph 77 % 1008 mb 0 mm/h
Tomorrow 12:00 am
weather icon
4° | 4°°C 0 mm 0% 5 mph 79 % 1007 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€72,781.79
-3.51%
Ethereum(ETH)
€1,703.80
-9.72%
Tether(USDT)
€0.92
-0.04%
XRP(XRP)
€1.85
-7.27%
Solana(SOL)
€109.59
-6.81%
USDC(USDC)
€0.92
0.01%
Dogecoin(DOGE)
€0.140780
-11.00%
Shiba Inu(SHIB)
€0.000010
-5.83%
Pepe(PEPE)
€0.000006
-6.76%