Die von China unterstützte Earth Baku weitet Cyberangriffe auf Europa, den Nahen Osten und Afrika aus

Teilen:

The China-backed threat actor known as Earth Baku has diversified its targeting footprint beyond the Indo-Pacific region to include Europe, the Middle East, and Africa starting in late 2022.

Newly targeted countries as part of the activity include Italy, Germany, the U.A.E., and Qatar, with suspected attacks also detected in Georgia and Romania. Governments, media and communications, telecoms, technology, healthcare, and education are some of the sectors singled out as part of the intrusion set.

“The group has updated its tools, tactics, and procedures (TTPs) in more recent campaigns, making use of public-facing applications such as IIS servers as entry points for attacks, after which they deploy sophisticated malware toolsets on the victim’s environment,” Trend Micro researchers Ted Lee and Theo Chen said in an analysis published last week.

The findings build upon recent reports from Zscaler and Google-owned Mandiant, which also detailed the threat actor’s use of malware families like DodgeBox (aka DUSTPAN) and MoonWalk (aka DUSTTRAP). Trend Micro has given them the monikers StealthReacher and SneakCross.

Earth Baku, a threat actor associated with APT41, is known for its use of StealthVector as far back as October 2020. Attack chains involve the exploitation of public-facing applications to drop the Godzilla web shell, which is then used to deliver follow-on payloads.

China-Backed Earth Baku

StealthReacher has been classified as an enhanced version of the StealthVector backdoor loader that’s responsible for launching SneakCross, a modular implant and a likely successor to ScrambleCross that leverages Google services for its command-and-control (C2) communication.

The attacks are also characterized by the use of other post-exploitation tools such as iox, Rakshasa, and a Virtual Private Network (VPN) service known as Tailscale. Exfiltration of sensitive data to the MEGA cloud storage service is accomplished by means of a command-line utility dubbed MEGAcmd.

“The group has employed new loaders such as StealthVector and StealthReacher, to stealthily launch backdoor components, and added SneakCross as their latest modular backdoor,” the researchers said.

“Earth Baku also used several tools during its post-exploitation including a customized iox tool, Rakshasa, TailScale for persistence, and MEGAcmd for efficient data exfiltration.”

Ravie Lakshmanan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
4:19 am, Juni 29, 2025
Wetter-Symbol 20°C
L: 19° | H: 20°
overcast clouds
Luftfeuchtigkeit: 81 %
Druck: 1024 mb
Wind: 10 mph WNW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:46 am
Sonnenuntergang: 9:21 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 20°°C 0 mm 0% 7 mph 82 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 35°°C 0.2 mm 20% 8 mph 67 % 1022 mb 0 mm/h
Di. Juli 01 10:00 pm
Wetter-Symbol
22° | 33°°C 0 mm 0% 10 mph 70 % 1017 mb 0 mm/h
Mi. Juli 02 10:00 pm
Wetter-Symbol
17° | 27°°C 1 mm 100% 12 mph 91 % 1018 mb 0 mm/h
Do. Juli 03 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 14 mph 93 % 1026 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
18° | 19°°C 0 mm 0% 5 mph 82 % 1024 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
22° | 23°°C 0 mm 0% 4 mph 65 % 1025 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 4 mph 41 % 1025 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
30° | 30°°C 0 mm 0% 4 mph 35 % 1023 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
28° | 28°°C 0 mm 0% 0 mph 34 % 1021 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
25° | 25°°C 0 mm 0% 7 mph 54 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 63 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
20° | 20°°C 0 mm 0% 4 mph 67 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,556.04
0.14%
Ethereum(ETH)
€2,075.63
0.56%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.87
0.48%
Solana(SOL)
€127.91
4.74%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.139229
0.83%
Shiba Inu(SHIB)
€0.000010
1.46%
Pepe(PEPE)
€0.000009
3.37%
Nach oben scrollen