Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Kurma

Also known as: tracked as, Parashuram, is a revered, TASPEN, civil servants

Description

Earth Kurma is an advanced persistent threat that focuses on government and telecommunications sectors across Southeast Asia, extending its reach to neighboring financial‑services, media, defense, energy and critical infrastructure organizations. The operators craft custom malware capable of installing kernel‑level rootkits (KRNRAT and MORIYA) for covert persistence. Once established they use a lightweight loader suite—DUNLOADER, TESDAT and DMLOADER—to deploy Cobalt Strike beacons and keylogging utilities such as KMLOG. Their exfiltration strategy is cloud‑centric: sensitive information is staged locally, often bundled in zip archives or placed within the victim’s %AppData% directory, and then transferred to publicly hosted storage through Dropbox or OneDrive accounts. The group also reuses code from earlier campaigns, leverages living‑off‑the‑land binaries such as syssetup.dll for stealth, and employs file hiding, process injection and in‑memory execution to avoid detection.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Financial services
Media
Defense
Energy
Critical infrastructure
Utilities

Targeted Countries / Regions

VN
SG
US
CN

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

Earth Kurma is a financially motivated APT that has targeted Southeast Asian governments and telecommunications providers since at least November 2020. The group deploys custom kernel‑level rootkits such as KRNRAT and MORIYA, along with loaders that seed Cobalt Strike beacons, to maintain persistence while exfiltrating data through trusted public cloud services like Dropbox and OneDrive.

Goals & Targeting

Earth Kurma’s primary objective appears to be financial gain through the acquisition of valuable data which can be leveraged or sold. They selectively target sectors that offer high-value intelligence—government, telecommunications, energy and critical infrastructure—in Southeast Asian nations such as Vietnam, Singapore, Malaysia, Thailand and the Philippines, with occasional activity noted against US or Chinese assets. Their tactics reflect a blend of tailored persistence mechanisms and stealthy exfiltration, aimed at extracting monetary value while evading security operations.

Enhanced Description

Key Capabilities

  • Deploy advanced custom malware and kernel‑level rootkits for persistence
  • Exfiltrate stolen data via public cloud services such as Dropbox and OneDrive
  • Target government and telecommunications organizations in Southeast Asia (and related sectors)
  • Perform lateral movement using SMB net use protocol
  • Conduct network reconnaissance with ICMP ping scans
  • Employ keylogging to harvest credentials
  • Execute process injection and memory‑resident payloads
  • Conceal files and processes for stealthy presence
  • Utilize living‑off‑the‑land binaries like syssetup.dll for covert operations
  • Adapt TTPs to victim environment, reusing code from prior campaigns
  • Leverage victim infrastructure and cloud platforms

MITRE ATT&CK Tactics

Persistence
Defense Evasion
Exfiltration
Execution
Credential Access

ATT&CK Techniques

T1014
T1071.004
T1041
T1046
T1021.002
T1059.001
T1056.001
T1055
T1070.004
T1071.001
T1036
T1552
T1110

Software / Tooling

TESDAT
SIMPOBOXSPY
KRNRAT
MORIYA
NBTSCAN
LADON
FRPC
WMIHACKER
ICMPinger
KMLOG
DUNLOADER
DMLOADER
Cobalt Strike
syssetup.dll

Campaigns & Victims

Earth Kurma first surfaced in late 2020, launching a series of campaign waves that exploited custom rootkits and lightweight loaders to embed Cobalt Strike beacons into government and telecom networks across Southeast Asia. The group’s operations exhibit a disciplined cadence, typically spanning a few weeks per attack phase, and frequently involve scanning for SMB shares before deploying keylogging utilities. While its financial motive dominates, the selection of high‑profile governmental and critical infrastructure targets suggests an agenda of influencing political or intelligence outcomes. Recent activity indicates evolving tool reuse practices, with newer iterations rebranding previously seen malware components to evade detection.

IOC Patterns

  • Use of public cloud storage services (Dropbox, OneDrive) for exfiltration
  • Deployment of kernel‑level rootkits such as KRNRAT and MORIYA
  • Custom malware toolset signatures and loaders (TESDAT, DUNLOADER)
  • File path targeting like %AppData%\Roaming\Microsoft\Windows\Libraries\infokey.zip
  • Use of syssetup.dll for INF file deployment and stealth
  • Process injection via NtCreateThreadEx syscall in ntdll.dll
  • Zip archives containing keylogging data or stolen credentials

Recommended Actions

  • Deploy endpoint detection and response solutions capable of detecting custom loaders TESDAT, DUNLOADER and SIMPOBOXSPY
  • Monitor outbound traffic to public cloud platforms (Dropbox, OneDrive) and flag abnormal upload patterns
  • Implement regular patching and monitor for unauthorized usage of kernel‑level rootkits KRNRAT/MORIYA or syssetup.dll loading
  • Block execution of known keylogging utilities such as KMLOG
  • Enforce least privilege on SMB shares and detect SMB net use activity to stop lateral movement
  • Configure intrusion detection systems to identify ICMP ping sweeps and network reconnaissance
  • Restrict execution of unofficial binaries like syssetup.dll; establish whitelisting policies for DLLs
  • Use host‑based IDS to flag process injection (T1055) and hidden processes (T1070.004)
  • Segment critical infrastructure networks from external cloud endpoints to mitigate exfiltration paths

Suggested Tags

APT
Rootkits
CloudExfiltration
GovernmentTarget
TelecomSector
EarthKurma
SoutheastAsia
Keylogger
MORIYA
SMB
ICMPScanning
CobaltStrike
CustomMalware
DataStaging

Confidence Assessment

The attribution to Earth Kurma is supported by multiple independent reports, indicating high confidence in the core TTPs and toolset inventory. However, gaps remain regarding precise operation dates, full geographic scope beyond Southeast Asia, and the extent of financial versus political motivations. Continuous monitoring and data sharing will be essential to refine these assessments.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.cloudsek.com — Cited by web research for: TASPEN
  2. apt.etda.or.th — Cited by web research for: Unknown
  3. www.trendmicro.com — Cited by web research for: Payload
  4. https://industrialcyber.co/ransomware/earth-kurma-apt-targets-southeast-asian-government-telecom-sectors-i — Cited by AI analysis.

Intel Summary

13

Techniques

51

Tools

0

Campaigns

59

IOCs

0

Observed Data

8

Tactics

Tags

APT
Backdoor / C2
Data Exfiltration
Government Targeting
espionage
government
telecommunications
south-east-asia
Rootkits
CloudExfiltration
GovernmentTarget
TelecomSector
EarthKurma
SoutheastAsia
Keylogger
MORIYA
SMB
ICMPScanning
CobaltStrike
CustomMalware
DataStaging

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.