Also known as: Storm-0978 targeting defense, government entities in Europe, North America, Storm-0978, Tropical Scorpius, UNC2596, Crouching Yeti, Berserk Bear, Dragonfly, Head Mare, YoroTrooper, SturgeonPhisher, Silent Lynx, Comrade Saiga, Tomiris, ShadowSilk, Transparent Tribe, UNC1549, Smoke Sandstorm, TA455, Imperial Kitten, 0ktapus, Octo Tempest, Scattered Spider, UNC961, Prophet Spider, SWORDLDR
Earth Baxia operates primarily from China with a stated motive of financial gain. The actor routinely targets government agencies, defense contractors, financial services and critical infrastructure across the world, especially in East Asia, Europe and North America. Initial infiltration is achieved through spear‑phishing campaigns that employ spoofed domains and crafted career‑portal emails carrying malicious archives such as .zip or .rar files. These archives often contain obfuscated PowerShell scripts, Office RCE payloads or WinRAR path‑traversal exploits (CVE‑2025‑8088/CVE‑2025‑6218) that execute code or deliver additional backdoors. Once inside, Earth Baxia leverages a variety of custom malware to maintain persistence and avoid detection. Their toolset includes customized Cobalt Strike components with altered signatures, the EAGLEDOOR multi‑protocol backdoor, SnipBot, RustyClaw, Mythic Agent, EAGLET, PhantomDL, Paper Werewolf/GOFFEE and MiniJunk. Advanced techniques such as DLL side‑loading into legitimate browsers (Edge.exe, msedge.dll) and Process Injection are employed to evade EDRs and gain privilege escalation. Infrastructure attacks also target public‐facing services: the group exploits a remote code execution vulnerability in GeoServer (CVE‑2024‑36401), a zero‑day on Cisco IOS Smart Install (CVE‑2018‑0171) and Office (CVE‑2023‑36884). In addition, they use firmware implants through SYNful Knock as well as SNMP tooling for persistence. Earth Baxia’s operations are coordinated via compromised email addresses, phishing domains in the .cfd/.xyz space, and often leverage malicious archives that hide alternate data streams (ADS) to conceal payloads.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Baxia is a China‐linked threat actor that targets defense, government and critical sectors across Europe, North America and APAC using spear‑phishing, zero‑day exploits and custom backdoors such as EAGLEDOOR. The group combines multiple delivery vectors—including Office CVE‑2023‑36884, WinRAR CVEs, Cisco IOS Smart Install flaws and GeoServer CVE‑2024‑36401—to gain initial footholds and persist via firmware implants, DLL hijacking and process injection.
Goals & Targeting
Earth Baxia’s strategic objectives appear primarily financially motivated while simultaneously pursuing espionage or sabotage against high‑value sectors. The actor selects targets that hold sensitive operational data—defense contractors, critical infrastructure operators, financial institutions—to exfiltrate privileged information or leverage it for ransom or blackmail. Their multi‑vector approach of phishing, zero‑day exploitation and firmware implants points to a desire for prolonged, stealthy presence that can supply lucrative intelligence or provide a foothold for future campaigns.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Baxia demonstrates a pattern of multi‑phase campaigns that combine phishing, zero‑day exploitation and implant distribution to achieve deep persistence. Their operations span multiple continents—Europe, North America, Africa, Asia and Oceania—and target broad spectra of sectors including defense, finance, telecommunications, energy and manufacturing. The actor deploys long‑term firmware implants and SNMP tooling while maintaining short‑lived backdoor channels such as EAGLEDOOR to exfiltrate data or pivot laterally. Past attacks highlight their adaptability to new software patches and willingness to pivot infrastructure when defenses are tightened.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in the core facts—such as Earth Baxia’s use of spear‑phishing, zero‑day CVEs, custom backdoors and firmware implants—is moderate to high based on multiple independent sources. However, gaps remain regarding exact operational timelines, sophistication level, precise infrastructure details, and attribution certainty beyond Chinese ties.
No campaigns linked yet.
No observed data linked yet.
4
Techniques
54
Tools
0
Campaigns
31
IOCs
0
Observed Data
3
Tactics