Also known as: CL-STA-0049, REF7707, tracked as, in Red Report 2026, Ink Dragon, Jewelbug, SHADOW-EARTH-053, targeting government, APT37, Ricochet Chollima, ScarCruft, Reaper Group, Spring Dragon, Billbug, manufacturing, telecom, Vietnam, Hong Kong, Rare Wolf, Belarusian, Ukrainian industrial enterprises, Gamaredon, verifying the signature, Shadows, Comet, Darkstar, to carry out attacks, APT44, BlackEnergy, PHANTOM, UAC-0133, Blue Echidna, Sandworm, UNK_CraftyCamel, ZDI-25-148, RudePanda, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, FROZENBARENTS, UAC-0113, Seashell Blizzard, UAC-0082, SANDWORM RELIC, Thrip
Earth Alux is a highly organized threat actor whose operations combine classic phishing techniques with advanced vulnerability exploitation. Recent analyses point to its use of password‑protected ZIP attachments that house LNK launchers, coupled with obfuscated C# loaders that tamper with registry autorun entries. Initial access is often gained via zero‑day exploits such as CVE‑2025‑0411 in 7‑Zip or the Windows .lnk shortcut vulnerability (ZDI‑CAN‑25373), enabling delivery of SmokeLoader, Smokeloader, Sagerunex, Merlin agent, VeilShell Trojans, and custom Go exfil modules. Once inside a network, Earth Alux establishes persistence through techniques like RAILSETTER — injecting malicious code into trusted processes such as mspaint.exe. Lateral movement is facilitated by RSBINJECT and MASQLOADER while collection tools scan hosts for system data. Command & Control typically relies on HTTP GET requests, sometimes mimicking legitimate traffic, and the group frequently emulates victim domain names to sidestep detection. The actor’s toolset also includes web shells (GODZILLA), backdoors such as VARGEIT and COBEACON, and publicly available RATs like AnyDesk. Exfiltration is achieved via DLL injection into svchost or dedicated Go binaries that push data over encrypted tunnel channels. These capabilities allow Earth Alux to maintain persistent footholds in targeted organizations and exfiltrate large volumes of sensitive information with relative stealth. Overall, Earth Alux demonstrates the hallmarks of a state‑backed espionage enterprise: meticulous staging, diversified attack vectors, and an infrastructure that combines stolen credentials, legitimate software, and zero‑days to achieve strategic objectives.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Alux is a China‑aligned APT known for sophisticated cyberespionage that blends spear‑phishing, zero‑day exploitation and custom backdoors. It targets high‑value sectors across Asia‑Pacific and Latin America, leveraging both legitimate tools (AnyDesk) and obscure vulnerabilities to move laterally and exfiltrate data. The group remains active amid evolving malware families such as Smokeloader and Sagerunex.
Goals & Targeting
Earth Alux’s primary objective is corporate and governmental intelligence gathering across geopolitically significant regions. By focusing on Asia‑Pacific, Latin America, and major industrial sectors—government, defense, telecommunications, energy, manufacturing, IT services, and finance—it seeks to acquire proprietary data that can influence national security or commercial advantage. The group’s use of legitimate RATs and zero‑day exploits underlines a strategy of low‑fingerprint infiltration designed to bypass perimeter defenses and maintain long‑term persistence for covert collection.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Alux’s campaigns are characterized by a high frequency of spear‑phishing events that target government and industry stakeholders in the Asia‑Pacific region, with spill‑over into Latin American entities. The attacker demonstrates an ability to pivot from initial compromise via surface‑level vulnerabilities or crafted attachments to deeper network infiltration, using lateral tools and custom RATs for persistence. Recent reports highlight a continued focus on exfiltrating classified data to cloud hosting and shadow infrastructure, suggesting a sustained operational tempo and the presence of well‑protected C2 channels.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based on a synthesis of multiple third‑party research reports and publicly disclosed indicators. While the overall picture—including spear‑phishing tactics, zero‑day exploitation, and the use of backdoor families such as Smokeloader—shows high confidence, gaps remain around precise attribution cadence, full toolchain inventory, and real‑time activity logs. Continued monitoring and cross‑validation with in‑house threat intel remain essential to refine the profile.
No campaigns linked yet.
No observed data linked yet.
9
Techniques
52
Tools
0
Campaigns
40
IOCs
0
Observed Data
6
Tactics