Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Krahang

Description

Earth Krahang is an APT group targeting government organizations worldwide. They use spear-phishing emails, weak internet-facing servers, and custom backdoors like Cobalt Strike, RESHELL, and XDealer to conduct cyber espionage. The group creates VPN servers on infected systems, employs brute force attacks on email accounts, and exploits compromised government infrastructure to attack other governments. Earth Krahang has been linked to another China-linked actor, Earth Lusca, and is believed to be part of a specialized task force for cyber espionage against government institutions.

AI Analysis

· 1 week ago

Executive Summary

Earth Krahang is a suspected advanced persistent threat (APT) group targeting government organizations globally. The group employs sophisticated tactics including spear-phishing, custom backdoors (e.g., Cobalt Strike), and brute-force attacks to conduct cyber espionage. Their activities are linked to another Chinese-linked actor, Earth Lusca, suggesting potential collaboration within a specialized task force.

Goals & Targeting

Earth Krahang's strategic objectives appear to center on cyber espionage, likely aimed at gathering sensitive government information for political or national security purposes. The group's targeting profile focuses on government institutions, suggesting a focus on high-value, information-rich sectors. Their global reach indicates that they may be seeking broad access to diverse geopolitical intelligence. The victimology suggests a preference for organizations with weaker cybersecurity defenses and internet-facing systems that can be exploited for initial access.

Enhanced Description

Earth Krahang is an APT group known for targeting government organizations worldwide. The group utilizes spear-phishing emails and weak internet-facing servers as initial infection vectors. Once inside the target network, they deploy custom backdoors such as Cobalt Strike, RESHshell, and XDealer to maintain persistence and elevate privileges. Earth Krahang has been observed creating VPN servers on infected systems to establish command-and-control (C2) communication channels, which allows them to further propagate within the network. They are also known to brute-force email accounts to gain access to additional internal resources. The group exploits compromised government infrastructure to target other nations, indicating a long-term strategic focus on cyber espionage. Earth Krahang's operations suggest a high level of technical sophistication and organizational support, as evidenced by their ability to maintain extensive campaigns over time. Their modus operandi includes lateral movement within networks, data exfiltration, and persistence mechanisms, all of which align with typical APT behaviors.

Key Capabilities

  • Spear-phishing campaigns
  • Custom backdoors (e.g., Cobalt Strike, RESHshell, XDealer)
  • VPNs for C2 communication
  • Brute-force email attacks
  • Lateral movement within networks
  • Data exfiltration capabilities

MITRE ATT&CK Tactics

Cyber Espionage
Initial Access
Lateral Movement
Exfiltration

ATT&CK Techniques

T1567.001 (Use of shared infrastructure)
T1055 (Remote Desktop Protocol)
T1021 (USB Dropping)
T1048 (Valid Accounts)
T1003 (Keyboard Dumping)
T1566.001 (OS Credential dumping)

Software / Tooling

Cobalt Strike
RESHshell
XDealer
Mimikatz
Custom RAT

Campaigns & Victims

Earth Krahang's campaign patterns include long-term, patient attacks that often go unnoticed. Their operational tempo suggests a methodical approach to network exploitation, with an emphasis on maintaining persistence and expanding access within the target environment. Past operations have targeted government institutions in multiple countries, indicating a global reach. Notable past operations include campaigns leveraging spear-phishing emails and custom malware, as well as brute-force attacks against email systems. Their collaboration with Earth Lusca suggests a potential larger network of cyber espionage actors linked to China.

IOC Patterns

  • Spear-phishing emails targeting government employees
  • Custom backdoor files dropped on infected systems
  • VPN server creation on compromised systems
  • Brute-force attempts on email accounts
  • Changes in DNS TLDs or domain name structures
  • Presence of Cobalt Strike beacons

Recommended Actions

  • Implement multi-factor authentication (MFA) for email and VPN services.
  • Regularly update and patch all internet-facing servers to mitigate exploitation vectors.
  • Monitor network traffic for signs of C2 communication channels, particularly encrypted VPN-like traffic.
  • Conduct user training to identify and report suspicious spear-phishing emails.
  • Use endpoint detection and response (EDR) tools to identify custom backdoor malware.
  • Segment sensitive networks and restrict access to critical systems.

Suggested Tags

APT
Cyber Espionage
Government Sector
Malware

Confidence Assessment

High confidence in Earth Krahang's classification as an APT group due to their sophisticated tactics and known tools. However, some details about their exact operational structure and motivations remain speculative, particularly regarding their linkage to Chinese state-sponsored actors. Further intelligence sharing between international agencies could provide additional clarity on their precise objectives and long-term goals.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Phishing
Backdoor / C2
Government Targeting
Cyber Espionage
Government Sector
Malware

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.