Also known as: Earth Baku, Blackfly, APT41, BlackTech, PLEAD, APT43, Kimsuky, a subset of APT41, WINNKIT, the Winnti rootkit, HIGHNOON, ELF_PLEAD, Hipid, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT
Earth Freybug, identified as a subset of APT41, is a cyberthreat group active since at least 2012, engaging in espionage and financially motivated activities across various sectors worldwide. The tactics, techniques, and procedures (TTPs) used in this campaign are similar to the ones from a campaign (Operation CuckooBees) described in an article published by Cybereason. They employ a diverse toolkit, including LOLBins and custom malware, to execute sophisticated cyberespionage attacks. The group's recent tactics involve DLL hijacking and API unhooking through a newly discovered malware named UNAPIMON, which prevents child processes from being monitored. This technique was observed in a vmtoolsd.exe process creating remote tasks to deploy malicious batch files for reconnaissance and backdoor access. UNAPIMON's simplicity and use of Microsoft Detours for defense evasion highlight the group's evolving methods and the need for vigilant security measures, such as restricting admin privileges and adhering to the principle of least privilege. Earth Freybug's persistence and creativity in refining their techniques underscore the ongoing threat they pose and the importance of proactive cybersecurity practices.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Freybug, a subset of APT41, has been active since at least 2012, focusing on cyberespionage with both financial and espionage motives. Known for employing advanced tactics such as DLL hijacking and API unhooking through custom malware like UNAPIMON, the group poses a significant threat to global sectors, particularly in Asia-Pacific regions.
Goals & Targeting
Earth Freybug targets various sectors worldwide, focusing on espionage and financial gain. Their focus on Asia-Pacific regions suggests strategic targeting of politically significant areas. Attacks target defense, tech, healthcare, and government sectors.
Enhanced Description
Earth Freybug is an APT group associated with APT41, known since at least 2012 for cyberespionage and financial activities. Their operations span various sectors globally, including defense, technology, healthcare, and government. They use a diverse toolkit including LOLBins and custom malware to execute sophisticated attacks. Recent observations include the use of UNAPIMON malware for API hooking and preventing child process monitoring, highlighting their evolving tactics. Earth Freybug's persistence and technical proficiency necessitate proactive security measures.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Freybug linked to APT41's infrastructure in China, targeting high-value assets. Patterns include long-term operations with targeted espionage campaigns. Notable for UNAPIMON malware used since 2023.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in their activity as part of APT41. Data gaps include specifics on resource infrastructure and exact targets outside linked campaigns.
No techniques linked yet.
No campaigns linked yet.
No observed data linked yet.
0
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
0
Tactics