Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors like Cobalt Strike, RESHELL, and XDealer to conduct cyber espionage. The group creates VPN servers on infected systems, employs brute force attacks on email accounts, and exploits compromised government infrastructure to attack other governments. Earth Krahang has been linked to another China-linked actor, Earth Lusca, and is believed to be part of a specialized task force for cyber espionage against government institutions.
Executive Summary
Earth Krahang is a suspected advanced persistent threat (APT) group targeting government organizations globally. The group employs sophisticated tactics including spear-phishing, custom backdoors (e.g., Cobalt Strike), and brute-force attacks to conduct cyber espionage. Their activities are linked to another Chinese-linked actor, Earth Lusca, suggesting potential collaboration within a specialized task force.
Goals & Targeting
Earth Krahang's strategic objectives appear to center on cyber espionage, likely aimed at gathering sensitive government information for political or national security purposes. The group's targeting profile focuses on government institutions, suggesting a focus on high-value, information-rich sectors. Their global reach indicates that they may be seeking broad access to diverse geopolitical intelligence. The victimology suggests a preference for organizations with weaker cybersecurity defenses and internet-facing systems that can be exploited for initial access.
Enhanced Description
Earth Krahang is an APT group known for targeting government organizations worldwide. The group utilizes spear-phishing emails and weak internet-facing servers as initial infection vectors. Once inside the target network, they deploy custom backdoors such as Cobalt Strike, RESHshell, and XDealer to maintain persistence and elevate privileges. Earth Krahang has been observed creating VPN servers on infected systems to establish command-and-control (C2) communication channels, which allows them to further propagate within the network. They are also known to brute-force email accounts to gain access to additional internal resources. The group exploits compromised government infrastructure to target other nations, indicating a long-term strategic focus on cyber espionage. Earth Krahang's operations suggest a high level of technical sophistication and organizational support, as evidenced by their ability to maintain extensive campaigns over time. Their modus operandi includes lateral movement within networks, data exfiltration, and persistence mechanisms, all of which align with typical APT behaviors.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Krahang's campaign patterns include long-term, patient attacks that often go unnoticed. Their operational tempo suggests a methodical approach to network exploitation, with an emphasis on maintaining persistence and expanding access within the target environment. Past operations have targeted government institutions in multiple countries, indicating a global reach. Notable past operations include campaigns leveraging spear-phishing emails and custom malware, as well as brute-force attacks against email systems. Their collaboration with Earth Lusca suggests a potential larger network of cyber espionage actors linked to China.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in Earth Krahang's classification as an APT group due to their sophisticated tactics and known tools. However, some details about their exact operational structure and motivations remain speculative, particularly regarding their linkage to Chinese state-sponsored actors. Further intelligence sharing between international agencies could provide additional clarity on their precise objectives and long-term goals.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics