Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Freybug

Also known as: Earth Baku, Blackfly, APT41, BlackTech, PLEAD, APT43, Kimsuky, a subset of APT41, WINNKIT, the Winnti rootkit, HIGHNOON, ELF_PLEAD, Hipid, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT

Description

Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities across various sectors worldwide. The tactics, techniques, and procedures (TTPs) used in this campaign are similar to the ones from a campaign (Operation CuckooBees) described in an article published by Cybereason. They employ a diverse toolkit, including LOLBins and custom malware, to execute sophisticated cyberespionage attacks. The group's recent tactics involve DLL hijacking and API unhooking through a newly discovered malware named UNAPIMON, which prevents child processes from being monitored. This technique was observed in a vmtoolsd.exe process creating remote tasks to deploy malicious batch files for reconnaissance and backdoor access. UNAPIMON's simplicity and use of Microsoft Detours for defense evasion highlight the group's evolving methods and the need for vigilant security measures, such as restricting admin privileges and adhering to the principle of least privilege. Earth Freybug's persistence and creativity in refining their techniques underscore the ongoing threat they pose and the importance of proactive cybersecurity practices.

Goals & Targeting

Targeted Sectors

Financial services
Defense
Government
Telecommunications
Education
Manufacturing
Transportation
Energy
Healthcare
Construction
Critical infrastructure
Chemical
Pharmaceutical
Gaming
Oil gas
Maritime
Retail
Hospitality
Media
Think tank

Targeted Countries / Regions

CN
TW
JP
KR
US
IN
PK
UA

AI Analysis

· 1 week ago

Executive Summary

Earth Freybug, a subset of APT41, has been active since at least 2012, focusing on cyberespionage with both financial and espionage motives. Known for employing advanced tactics such as DLL hijacking and API unhooking through custom malware like UNAPIMON, the group poses a significant threat to global sectors, particularly in Asia-Pacific regions.

Goals & Targeting

Earth Freybug targets various sectors worldwide, focusing on espionage and financial gain. Their focus on Asia-Pacific regions suggests strategic targeting of politically significant areas. Attacks target defense, tech, healthcare, and government sectors.

Enhanced Description

Earth Freybug is an APT group associated with APT41, known since at least 2012 for cyberespionage and financial activities. Their operations span various sectors globally, including defense, technology, healthcare, and government. They use a diverse toolkit including LOLBins and custom malware to execute sophisticated attacks. Recent observations include the use of UNAPIMON malware for API hooking and preventing child process monitoring, highlighting their evolving tactics. Earth Freybug's persistence and technical proficiency necessitate proactive security measures.

Key Capabilities

  • Use of LOLBins for persistence
  • Custom malware development
  • DLL hijacking techniques
  • API unhooking
  • Defense evasion via Detours

MITRE ATT&CK Tactics

Reconnaissance
Defense Evasion
Credential Access
Lateral Movement
Exfiltration Activities
Impact Actions

ATT&CK Techniques

T1055
T1566.001
T1270
T1003.001
T1486
T1555.002

Software / Tooling

Cobalt Strike
UNAPIMON

Campaigns & Victims

Earth Freybug linked to APT41's infrastructure in China, targeting high-value assets. Patterns include long-term operations with targeted espionage campaigns. Notable for UNAPIMON malware used since 2023.

IOC Patterns

  • Lateral movement via VM tools
  • Scheduled task creation by vmtoolsd.exe
  • Dropped malicious batch files

Recommended Actions

  • Implement advanced monitoring for Windows processes
  • Restrict admin access
  • Segment network and implement micro-permissions
  • Patch systems regularly
  • Enable threat detection with logs
  • Educate employees on phishing
  • Encrypt backups
  • Conduct regular incident response drills

Suggested Tags

APT
espionage
アジア太平洋地域
金融espionage
採掘業界
ターゲット持続化

Confidence Assessment

High confidence in their activity as part of APT41. Data gaps include specifics on resource infrastructure and exact targets outside linked campaigns.

ATT&CK Techniques

No techniques linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 1 Domain 2 Filename 13 SHA-256 Hash 4

References

  1. blogs.jpcert.or.jp — Cited by web research for: BlackTech
  2. www.trendmicro.com — Cited by web research for: a subset of APT41
  3. jsac.jpcert.or.jp — Cited by web research for: WINNKIT
  4. apt.etda.or.th — Cited by web research for: Unknown
  5. www.trendmicro.com — Cited by web research for: Payload
  6. apt.etda.or.th — Cited by web research for: HIGHNOON

Intel Summary

0

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
espionage
アジア太平洋地域
金融espionage
採掘業界
ターゲット持続化

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.