Also known as: tracked as, Parashuram, is a revered, TASPEN, civil servants
Earth Kurma is an advanced persistent threat that focuses on government and telecommunications sectors across Southeast Asia, extending its reach to neighboring financial‑services, media, defense, energy and critical infrastructure organizations. The operators craft custom malware capable of installing kernel‑level rootkits (KRNRAT and MORIYA) for covert persistence. Once established they use a lightweight loader suite—DUNLOADER, TESDAT and DMLOADER—to deploy Cobalt Strike beacons and keylogging utilities such as KMLOG. Their exfiltration strategy is cloud‑centric: sensitive information is staged locally, often bundled in zip archives or placed within the victim’s %AppData% directory, and then transferred to publicly hosted storage through Dropbox or OneDrive accounts. The group also reuses code from earlier campaigns, leverages living‑off‑the‑land binaries such as syssetup.dll for stealth, and employs file hiding, process injection and in‑memory execution to avoid detection.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Kurma is a financially motivated APT that has targeted Southeast Asian governments and telecommunications providers since at least November 2020. The group deploys custom kernel‑level rootkits such as KRNRAT and MORIYA, along with loaders that seed Cobalt Strike beacons, to maintain persistence while exfiltrating data through trusted public cloud services like Dropbox and OneDrive.
Goals & Targeting
Earth Kurma’s primary objective appears to be financial gain through the acquisition of valuable data which can be leveraged or sold. They selectively target sectors that offer high-value intelligence—government, telecommunications, energy and critical infrastructure—in Southeast Asian nations such as Vietnam, Singapore, Malaysia, Thailand and the Philippines, with occasional activity noted against US or Chinese assets. Their tactics reflect a blend of tailored persistence mechanisms and stealthy exfiltration, aimed at extracting monetary value while evading security operations.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Kurma first surfaced in late 2020, launching a series of campaign waves that exploited custom rootkits and lightweight loaders to embed Cobalt Strike beacons into government and telecom networks across Southeast Asia. The group’s operations exhibit a disciplined cadence, typically spanning a few weeks per attack phase, and frequently involve scanning for SMB shares before deploying keylogging utilities. While its financial motive dominates, the selection of high‑profile governmental and critical infrastructure targets suggests an agenda of influencing political or intelligence outcomes. Recent activity indicates evolving tool reuse practices, with newer iterations rebranding previously seen malware components to evade detection.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The attribution to Earth Kurma is supported by multiple independent reports, indicating high confidence in the core TTPs and toolset inventory. However, gaps remain regarding precise operation dates, full geographic scope beyond Southeast Asia, and the extent of financial versus political motivations. Continuous monitoring and data sharing will be essential to refine these assessments.
No campaigns linked yet.
No observed data linked yet.
13
Techniques
51
Tools
0
Campaigns
59
IOCs
0
Observed Data
8
Tactics