Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Baxia

Also known as: Storm-0978 targeting defense, government entities in Europe, North America, Storm-0978, Tropical Scorpius, UNC2596, Crouching Yeti, Berserk Bear, Dragonfly, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, SWORDLDR

Description

Earth Baxia operates primarily from China with a stated motive of financial gain. The actor routinely targets government agencies, defense contractors, financial services and critical infrastructure across the world, especially in East Asia, Europe and North America. Initial infiltration is achieved through spear‑phishing campaigns that employ spoofed domains and crafted career‑portal emails carrying malicious archives such as .zip or .rar files. These archives often contain obfuscated PowerShell scripts, Office RCE payloads or WinRAR path‑traversal exploits (CVE‑2025‑8088/CVE‑2025‑6218) that execute code or deliver additional backdoors. Once inside, Earth Baxia leverages a variety of custom malware to maintain persistence and avoid detection. Their toolset includes customized Cobalt Strike components with altered signatures, the EAGLEDOOR multi‑protocol backdoor, SnipBot, RustyClaw, Mythic Agent, EAGLET, PhantomDL, Paper Werewolf/GOFFEE and MiniJunk. Advanced techniques such as DLL side‑loading into legitimate browsers (Edge.exe, msedge.dll) and Process Injection are employed to evade EDRs and gain privilege escalation. Infrastructure attacks also target public‐facing services: the group exploits a remote code execution vulnerability in GeoServer (CVE‑2024‑36401), a zero‑day on Cisco IOS Smart Install (CVE‑2018‑0171) and Office (CVE‑2023‑36884). In addition, they use firmware implants through SYNful Knock as well as SNMP tooling for persistence. Earth Baxia’s operations are coordinated via compromised email addresses, phishing domains in the .cfd/.xyz space, and often leverage malicious archives that hide alternate data streams (ADS) to conceal payloads.

Goals & Targeting

Targeted Sectors

Government
Financial services
Telecommunications
Defense
Manufacturing
Transportation
Critical infrastructure
Education
Healthcare
Energy
Aviation
Retail
Aerospace
Media
Oil gas
Food agriculture
Construction
Mining
Entertainment
Utilities
Information technology
Legal services
Hospitality

Targeted Countries / Regions

CN
TW
RU
US
BY
AU
KZ
BR
KR
JP
CA
SG
VN
TR
KP
GB
EG
IR

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 days ago

Executive Summary

Earth Baxia is a China‐linked threat actor that targets defense, government and critical sectors across Europe, North America and APAC using spear‑phishing, zero‑day exploits and custom backdoors such as EAGLEDOOR. The group combines multiple delivery vectors—including Office CVE‑2023‑36884, WinRAR CVEs, Cisco IOS Smart Install flaws and GeoServer CVE‑2024‑36401—to gain initial footholds and persist via firmware implants, DLL hijacking and process injection.

Goals & Targeting

Earth Baxia’s strategic objectives appear primarily financially motivated while simultaneously pursuing espionage or sabotage against high‑value sectors. The actor selects targets that hold sensitive operational data—defense contractors, critical infrastructure operators, financial institutions—to exfiltrate privileged information or leverage it for ransom or blackmail. Their multi‑vector approach of phishing, zero‑day exploitation and firmware implants points to a desire for prolonged, stealthy presence that can supply lucrative intelligence or provide a foothold for future campaigns.

Enhanced Description

Key Capabilities

  • Spear‑phishing with malicious attachments and spoofed domains
  • Exploitation of Office CVE‑2023‑36884
  • Exploitation of WinRAR CVE‑2025‑8088/CVE‑2025‑6218 path‑traversal zero‑days
  • Exploitation of Cisco IOS Smart Install vulnerability (CVE‑2018‑0171)
  • Exploitation of GeoServer CVE‑2024‑36401 for remote code execution
  • Delivery of customized backdoors: SnipBot, RustyClaw, Mythic Agent, EAGLET/EAGLEDOOR, PhantomDL, Paper Werewolf/GOFFEE, MiniJunk, MiniBrowse
  • Use of alternate data streams to hide payloads within archives
  • Silent archive extraction deployment
  • Firmware implants via SYNful Knock and SNMP tooling persistence
  • DLL side‑loading/hijacking into trusted binary executables (Edge.exe, Chrome updater)
  • Process injection and anti‑EDR techniques
  • Lightweight credential stealer targeting Chrome/Edge browsers

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1566.001
T1068
T1203
T1190

Software / Tooling

PlugX
Akira
Agent Tesla
ConnectWise
Phishing tools
Spear‑Phishing
PowerShell
Interlock ransomware
Cobalt Strike (customized components)
Charon
Gentlemen
Global MINIBIKE
PhantomCore
PipeMagic
STOP
WarLock
ClickFix
ScreenConnect
Ransomware payloads
Earth Berberoka
GamblingPuppet
Gunra
Trojan
Nimbus Manticore
Subtle Snail
ToolShell
GhostRedirector
SnipBot
RustyClaw
Mythic Agent
EAGLET
PhantomDL
Paper Werewolf
GOFFEE
MiniJunk
MiniBrowse

Campaigns & Victims

Earth Baxia demonstrates a pattern of multi‑phase campaigns that combine phishing, zero‑day exploitation and implant distribution to achieve deep persistence. Their operations span multiple continents—Europe, North America, Africa, Asia and Oceania—and target broad spectra of sectors including defense, finance, telecommunications, energy and manufacturing. The actor deploys long‑term firmware implants and SNMP tooling while maintaining short‑lived backdoor channels such as EAGLEDOOR to exfiltrate data or pivot laterally. Past attacks highlight their adaptability to new software patches and willingness to pivot infrastructure when defenses are tightened.

IOC Patterns

  • CVE identifiers
  • Phishing domain URLs/DNS infrastructure
  • File archive names and extensions (.rar, .zip)
  • Alternate Data Stream usage
  • DLL side‑loading/hijacking patterns
  • Multi‑protocol backdoor signatures (EAGLEDOOR)

Recommended Actions

  • Patch Office, WinRAR, Cisco IOS immediately to close CVE‑2023‑36884, CVE‑2025‑8088/CVE‑2025‑6218, and CVE‑2018‑0171.
  • Disable or patch vulnerable Smart Install on Cisco devices.
  • Block known phishing domains and spoofed email addresses linked to Earth Baxia.
  • Implement application whitelisting to detect malicious attachments and archived payloads.
  • Monitor DLL side‑loading/hijacking into trusted binaries such as Edge.exe, Chrome updater executables.
  • Detect and block process injection patterns; enable behavioral EDR indicators for DLL injection. Audit SNMP traffic for unconventional SYNful Knock activity; review firmware integrity on network devices. Harden GeoServer instances or apply patches to remediate CVE‑2024‑36401. Deploy endpoint detection that flags custom Cobalt Strike components and multi‑protocol backdoor traffic (HTTP/HTTPS/SMB).

Suggested Tags

APT
China‑linked
Phishing
Zero‑Day Exploitation
Backdoor Deployment
Defense Evasion
Firmware Implant
Remote Code Execution
Cobalt Strike Customization
Rich Attachment Delivery
Credential Stealer
Multi‑Sector Targeting
Government & Critical Infrastructure Focus

Confidence Assessment

Confidence in the core facts—such as Earth Baxia’s use of spear‑phishing, zero‑day CVEs, custom backdoors and firmware implants—is moderate to high based on multiple independent sources. However, gaps remain regarding exact operational timelines, sophistication level, precise infrastructure details, and attribution certainty beyond Chinese ties.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 8 Domain 9 IPv4 Address 3

References

  1. www.fortinet.com — Cited by web research for: Storm-0978 targeting defense
  2. ics-cert.kaspersky.com — Cited by web research for: Storm-0978
  3. www.trendmicro.com — Cited by web research for: SWORDLDR
  4. www.trendmicro.com — Cited by web research for: STOP

Intel Summary

4

Techniques

54

Tools

0

Campaigns

31

IOCs

0

Observed Data

3

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
espionage
government-targeted
Asia-Pacific
China‑linked
Zero‑Day Exploitation
Backdoor Deployment
Defense Evasion
Firmware Implant
Remote Code Execution
Cobalt Strike Customization
Rich Attachment Delivery
Credential Stealer
Multi‑Sector Targeting
Government & Critical Infrastructure Focus

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.