Also known as: tracked as, the centripetal, balancing, centrifugal forces, the Newscaster Team, Ea, were reptilian in appearance, NosyDoor, Flax Typhoon, RedJuliett, Ethereal Panda
Earth Naga has emerged as a highly capable espionage unit that persistently targets government agencies, telecommunications firms, military‐related manufacturers, utilities, financial services, media outlets and education institutions. The group employs a sophisticated, modular toolkit: shellcode loaders such as Draculoader, generic stagers (SNOWLIGHT/Vshell), and .NET malware families (NetDraft/FINALDRAFT) that leverage legitimate Microsoft Graph API channels for command‑and‑control. It frequently exploits high‑impact zero‑day CVEs—including CVE‑2025‑0994, 20333 and 20362—to gain initial footholds and to target Citrix devices via CVE‑2025‑5777. Operationally, Earth Naga exhibits a blend of classic APT techniques and emerging tactics. It sets up proxy servers (Stowaway) to tunnel exfiltration traffic through legitimate cloud services or even blockchain transactions, thereby evading traditional perimeter sensors. The actor also deploys a portfolio of RAT families (DeedRAT, SNAPPYBEE) and DLL‑based backdoors such as ZingDoor, with persistent rootkits (e.g., SHADOW‑EARTH‑067) to maintain kernel‑level persistence. A notable aspect of their operations is the integration of AI‑driven autonomous agents that facilitate reconnaissance, credential harvesting and lateral movement across victim networks. These capabilities are bolstered by collaboration with Earth Estries, which acts as an access‑broker providing shared ingress points and complicating attribution efforts.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Naga is a sophisticated APT actor focused on espionage against high‑value targets such as government agencies, defense contractors and critical infrastructure across APAC, the US, EU and Latin America. The group uses a multilayered toolkit—including shellcode loaders, .NET stagers that piggyback on Microsoft Graph API, RAT families and zero‑day exploits—to maintain persistence, move laterally and exfiltrate data covertly via cloud services and custom proxy tunnels. Recent operations show collaboration with the Earth Estries access‑broker network, complicating attribution and expanding reach.
Goals & Targeting
Earth Naga’s primary objective is long‑term intelligence collection in strategically sensitive sectors—national security, defense logistics, telecom infrastructure and critical utilities—in order to support geopolitical objectives of its sponsoring nation. By targeting a mix of government entities, defense contractors, media organizations, and financial service firms, the actor seeks to harvest actionable data on technology, policy, and economic trends. The collaboration with Earth Estries indicates a cross‑border operational model that extends reach into NATO member states and Latin American markets, broadening its intelligence footprint while obfuscating attribution.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Naga operates with a sustained, long‑term campaign model that cycles through initial compromise, covert persistence, lateral expansion and data exfiltration. The group frequently launches spearphishing campaigns and exploits unpatched zero‑days to infiltrate high‑value networks across Taiwan, broader APAC, the United States, Europe (including NATO members), and Latin America. Its operations display rapid adaptation—shifting between cloud‑based command channels and custom proxy tunnels—to evade detection. Collaboration with the Earth Estries access‑broker network suggests a modular supply‑chain strategy that can scale and redistribute compromised credentials to multiple downstream actors.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The evidence for Earth Naga’s capabilities and operational behaviors is drawn from multiple independent intelligence reports, providing moderate to high confidence in the identified tactics, techniques, and toolset. However, gaps remain regarding precise attribution, exact timelines of activity, and the full extent of collaboration with Earth Estries. Continuous intelligence updates and telemetry correlation are required to refine threat assessment and validate emerging campaign patterns.
No campaigns linked yet.
No observed data linked yet.
7
Techniques
53
Tools
0
Campaigns
40
IOCs
0
Observed Data
5
Tactics