Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Alux

Also known as: CL-STA-0049, REF7707, tracked as, in Red Report 2026, Ink Dragon, Jewelbug, SHADOW-EARTH-053, targeting government, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148, RudePanda, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, SANDWORM RELIC, Thrip

Description

Earth Alux is a highly organized threat actor whose operations combine classic phishing techniques with advanced vulnerability exploitation. Recent analyses point to its use of password‑protected ZIP attachments that house LNK launchers, coupled with obfuscated C# loaders that tamper with registry autorun entries. Initial access is often gained via zero‑day exploits such as CVE‑2025‑0411 in 7‑Zip or the Windows .lnk shortcut vulnerability (ZDI‑CAN‑25373), enabling delivery of SmokeLoader, Smokeloader, Sagerunex, Merlin agent, VeilShell Trojans, and custom Go exfil modules. Once inside a network, Earth Alux establishes persistence through techniques like RAILSETTER — injecting malicious code into trusted processes such as mspaint.exe. Lateral movement is facilitated by RSBINJECT and MASQLOADER while collection tools scan hosts for system data. Command & Control typically relies on HTTP GET requests, sometimes mimicking legitimate traffic, and the group frequently emulates victim domain names to sidestep detection. The actor’s toolset also includes web shells (GODZILLA), backdoors such as VARGEIT and COBEACON, and publicly available RATs like AnyDesk. Exfiltration is achieved via DLL injection into svchost or dedicated Go binaries that push data over encrypted tunnel channels. These capabilities allow Earth Alux to maintain persistent footholds in targeted organizations and exfiltrate large volumes of sensitive information with relative stealth. Overall, Earth Alux demonstrates the hallmarks of a state‑backed espionage enterprise: meticulous staging, diversified attack vectors, and an infrastructure that combines stolen credentials, legitimate software, and zero‑days to achieve strategic objectives.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Manufacturing
Transportation
Financial services
Defense
Energy
Critical infrastructure
Retail
Construction
Oil gas
Maritime
Pharmaceutical
Information technology
Healthcare
Aerospace
Aviation
Education
Entertainment
Utilities
Nuclear
Mining
Media
Chemical
Legal services

Targeted Countries / Regions

CN
RU
US
BR
TW
AE
VN
JP
UA
KR
SG
GB
PK
IL
IR
AU
PL
NL
europe

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Earth Alux is a China‑aligned APT known for sophisticated cyberespionage that blends spear‑phishing, zero‑day exploitation and custom backdoors. It targets high‑value sectors across Asia‑Pacific and Latin America, leveraging both legitimate tools (AnyDesk) and obscure vulnerabilities to move laterally and exfiltrate data. The group remains active amid evolving malware families such as Smokeloader and Sagerunex.

Goals & Targeting

Earth Alux’s primary objective is corporate and governmental intelligence gathering across geopolitically significant regions. By focusing on Asia‑Pacific, Latin America, and major industrial sectors—government, defense, telecommunications, energy, manufacturing, IT services, and finance—it seeks to acquire proprietary data that can influence national security or commercial advantage. The group’s use of legitimate RATs and zero‑day exploits underlines a strategy of low‑fingerprint infiltration designed to bypass perimeter defenses and maintain long‑term persistence for covert collection.

Enhanced Description

Key Capabilities

  • Spear‑phishing with password‑protected ZIP attachments containing LNK launchers
  • Obfuscated C# loaders that disable autoruns via registry modifications
  • In‑memory execution of decrypted DLLs and PowerShell scripts
  • Exploitation of zero‑day vulnerabilities: CVE‑2025‑0411 7‑Zip, CVE‑2025‑55182 React2Shell, Windows .lnk shortcut flaw (ZDI‑CAN‑25373)
  • Double‑archiving to bypass Mark‑of‑the‑Web protection
  • Delivery via remote administration tools such as AnyDesk
  • Deployment of web shells like GODZILLA and backdoors VARGEIT, COBEACON, Sagerunex, Smokeloader, Merlin agent, VeilShell Trojans
  • Use of HTTP GET requests for C&C communication instead of POST
  • Exfiltration through DLL injection into svchost or custom Go exfil modules
  • System data collection and host profiling
  • Imitation/matching victim domain names (domain spoofing)
  • LNK shortcut execution with hidden command‑line arguments
  • Persistence via RAILSETTER injections in trusted processes
  • Lateral movement with RSBINJECT and MASQLOADER

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Persistence
Command and Control
Exfiltration

ATT&CK Techniques

T1566.002
T1059.001
T1112
T1203
T1071.001
T1041
T1190
T1105

Software / Tooling

Smokeloader
Sagerunex backdoor
Merlin agent
VeilShell Trojan
C#‑based obfuscated loader
Loki
ShadowPad
NOODLERAT
AnyDesk
Jewelbug
GODZILLA web shell
VARGEIT backdoor
COBEACON backdoor
RSBINJECT
MASQLOADER
RAILSETTER

Campaigns & Victims

Earth Alux’s campaigns are characterized by a high frequency of spear‑phishing events that target government and industry stakeholders in the Asia‑Pacific region, with spill‑over into Latin American entities. The attacker demonstrates an ability to pivot from initial compromise via surface‑level vulnerabilities or crafted attachments to deeper network infiltration, using lateral tools and custom RATs for persistence. Recent reports highlight a continued focus on exfiltrating classified data to cloud hosting and shadow infrastructure, suggesting a sustained operational tempo and the presence of well‑protected C2 channels.

IOC Patterns

  • Password‑protected ZIP attachment in spear‑phishing emails
  • LNK shortcut file execution
  • Obfuscated DLL/C# loader disabling autorun via registry
  • Double archiving to bypass Mark‑of‑the‑Web protection
  • Zero‑day CVE‑2025‑0411 7‑Zip exploitation
  • .lnk shortcut files with hidden command‑line arguments
  • HTTP GET for C&C communication instead of POST
  • DLL injected into svchost process for exfiltration
  • Domain names mimicking victim domains
  • Custom Go-based exfiltration modules
  • CVE‑2025‑55182 React2Shell exploitation patterns
  • Use of legitimate remote administration tools like AnyDesk

Recommended Actions

  • Patch CVE‑2025‑0411 (7‑Zip) and other active Windows vulnerabilities immediately.
  • Block or harden controls around password‑protected ZIP attachments in inbound email flows.
  • Deploy EDR solutions tuned to detect obfuscated DLL/C# loaders, LNK file execution, and registry modifications that disable autoruns.
  • Monitor for abnormal HTTP GET traffic originating from host processes and enforce stricter application whitelisting for unknown DLLs in svchost.
  • Implement network segmentation and monitor lateral movement tooling such as RSBINJECT and MASQLOADER via IDS/IPS signatures.
  • Use endpoint detection to alert on known backdoor binaries (Sagerunex, Smokeloader, Merlin) and custom Go exfil modules.
  • Leverage domain filtering or reputation services to detect newly registered domains that spoof legitimate sites.
  • Employ secure configuration hardening for remote administration tools, limiting AnyDesk usage via policy or network controls.

Suggested Tags

spear-phishing
phishing-attachment
CVE-2025-0411
Smokeloader
Sagerunex
Merlin agent
VeilShell Trojan
PowerShell attack
backdoor
obfuscation
APT
Shadow-Earth-053
China-Aligned
Government Target
Defense Sector
CVE Exploitation
.lnk Vulnerability
Remote Administration Tool
Go Malware
Asia-Pacific region
Latin America
technology sector
logistics sector
manufacturing sector
telecommunications sector
IT services sector
retail sector
government sector

Confidence Assessment

The assessment is based on a synthesis of multiple third‑party research reports and publicly disclosed indicators. While the overall picture—including spear‑phishing tactics, zero‑day exploitation, and the use of backdoor families such as Smokeloader—shows high confidence, gaps remain around precise attribution cadence, full toolchain inventory, and real‑time activity logs. Continued monitoring and cross‑validation with in‑house threat intel remain essential to refine the profile.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT37
  2. research.checkpoint.com — Cited by web research for: RudePanda
  3. www.trendmicro.com — Cited by web research for: Evil-CreateDump
  4. www.trendmicro.com — Cited by web research for: Information Technology
  5. lp.kaspersky.com — Cited by web research for: Netherlands
  6. https://www.picussecurity.com/resource/blog/t1486-data-encrypted-for-impact-in-mitre-attack-explained — Cited by AI analysis.
  7. https://thehackernews.com/2026/05/china-linked-hackers-target-asian.html — Cited by AI analysis.
  8. https://www.broadcom.com/support/security-center/protection-bulletin/recent-jewelbug-apt-activity — Cited by AI analysis.

Intel Summary

9

Techniques

52

Tools

0

Campaigns

40

IOCs

0

Observed Data

6

Tactics

Tags

APT
Backdoor / C2
Government Targeting
espionage
China-linked
cyberespionage
government targeting
APAC
Latin America
spear-phishing
phishing-attachment
CVE-2025-0411
Smokeloader
Sagerunex
Merlin agent
VeilShell Trojan
PowerShell attack
backdoor
obfuscation
Shadow-Earth-053
China-Aligned
Government Target
Defense Sector
CVE Exploitation
.lnk Vulnerability
Remote Administration Tool
Go Malware
Asia-Pacific region
technology sector
logistics sector
manufacturing sector
telecommunications sector
IT services sector
retail sector
government sector

Details

Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.