Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Naga

Also known as: tracked as, the centripetal, balancing, centrifugal forces, the Newscaster Team, Ea, were reptilian in appearance, NosyDoor, Flax Typhoon, RedJuliett, Ethereal Panda

Description

Earth Naga has emerged as a highly capable espionage unit that persistently targets government agencies, telecommunications firms, military‐related manufacturers, utilities, financial services, media outlets and education institutions. The group employs a sophisticated, modular toolkit: shellcode loaders such as Draculoader, generic stagers (SNOWLIGHT/Vshell), and .NET malware families (NetDraft/FINALDRAFT) that leverage legitimate Microsoft Graph API channels for command‑and‑control. It frequently exploits high‑impact zero‑day CVEs—including CVE‑2025‑0994, 20333 and 20362—to gain initial footholds and to target Citrix devices via CVE‑2025‑5777. Operationally, Earth Naga exhibits a blend of classic APT techniques and emerging tactics. It sets up proxy servers (Stowaway) to tunnel exfiltration traffic through legitimate cloud services or even blockchain transactions, thereby evading traditional perimeter sensors. The actor also deploys a portfolio of RAT families (DeedRAT, SNAPPYBEE) and DLL‑based backdoors such as ZingDoor, with persistent rootkits (e.g., SHADOW‑EARTH‑067) to maintain kernel‑level persistence. A notable aspect of their operations is the integration of AI‑driven autonomous agents that facilitate reconnaissance, credential harvesting and lateral movement across victim networks. These capabilities are bolstered by collaboration with Earth Estries, which acts as an access‑broker providing shared ingress points and complicating attribution efforts.

Goals & Targeting

Targeted Sectors

Government
Telecommunications
Defense
Retail
Financial services
Critical infrastructure
Utilities
Information technology
Education
Manufacturing
Media

Targeted Countries / Regions

CN
IR
KP
RU
US
UA
JP
TW

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

Earth Naga is a sophisticated APT actor focused on espionage against high‑value targets such as government agencies, defense contractors and critical infrastructure across APAC, the US, EU and Latin America. The group uses a multilayered toolkit—including shellcode loaders, .NET stagers that piggyback on Microsoft Graph API, RAT families and zero‑day exploits—to maintain persistence, move laterally and exfiltrate data covertly via cloud services and custom proxy tunnels. Recent operations show collaboration with the Earth Estries access‑broker network, complicating attribution and expanding reach.

Goals & Targeting

Earth Naga’s primary objective is long‑term intelligence collection in strategically sensitive sectors—national security, defense logistics, telecom infrastructure and critical utilities—in order to support geopolitical objectives of its sponsoring nation. By targeting a mix of government entities, defense contractors, media organizations, and financial service firms, the actor seeks to harvest actionable data on technology, policy, and economic trends. The collaboration with Earth Estries indicates a cross‑border operational model that extends reach into NATO member states and Latin American markets, broadening its intelligence footprint while obfuscating attribution.

Enhanced Description

Key Capabilities

  • Deploy shellcode loaders such as Draculoader
  • Use generic stagers (SNOWLIGHT/Vshell)
  • Install .NET malware leveraging Microsoft Graph API for C2
  • Deploy RAT families DeedRAT and SNAPPYBEE with DLL backdoors like ZingDoor
  • Exploit zero‑day CVEs (CVE‑2025‑0994, 20333, 20362, 5777)
  • Set up proxy tunneling via Stowaway to exfiltrate data covertly
  • Employ AI‑driven autonomous agents for reconnaissance and lateral movement
  • Hide command‑and‑control channels within legitimate cloud services or blockchain transactions
  • Provide access brokerage services for shared ingress

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Command and Control
Exfiltration

ATT&CK Techniques

T1190
T1566.001
T1068
T1105
T1074
T1090
T1059.001

Software / Tooling

Draculoader
SNOWLIGHT
NetDraft
FINALDRAFT
SquidDoor
DeedRAT
SNAPPYBEE
ZingDoor
VSHELL
ToolShell
Stowaway
BYOVD rootkit SHADOW‑EARTH‑067
AI-driven autonomous agent
ShadowPad
TrillClient
Earth Naga backdoor
Kazuar
GlassWorm

Campaigns & Victims

Earth Naga operates with a sustained, long‑term campaign model that cycles through initial compromise, covert persistence, lateral expansion and data exfiltration. The group frequently launches spearphishing campaigns and exploits unpatched zero‑days to infiltrate high‑value networks across Taiwan, broader APAC, the United States, Europe (including NATO members), and Latin America. Its operations display rapid adaptation—shifting between cloud‑based command channels and custom proxy tunnels—to evade detection. Collaboration with the Earth Estries access‑broker network suggests a modular supply‑chain strategy that can scale and redistribute compromised credentials to multiple downstream actors.

IOC Patterns

  • Zero‑day CVE exploitation (CVE‑2025‑0994, 20333, 20362, 5777)
  • Command-and-control through legitimate cloud services such as Microsoft Graph API or GitHub
  • Proxy tunneling via Stowaway for covert traffic routing
  • DLL-based backdoors and .NET malware leveraging cloud APIs
  • Specific IPs/domains used by ShadowPad C&C (e.g., 45.92.158.50)

Recommended Actions

  • Patch promptly against known zero‑day vulnerabilities (CVE‑2025‑0994, 20333, 20362, 5777).
  • Strengthen email security to detect spearphishing and watering-hole campaigns.
  • Monitor outbound traffic for anomalous usage of Microsoft Graph API, GitHub or public blockchain transactions and block suspicious connections.
  • Deploy EDR solutions capable of detecting proxy tunneling tools (Stowaway) and DLL backdoors like ZingDoor.
  • Implement rootkit detection and BYOVD protection to counter kernel‑level stealth malware.
  • Invest in AI/ML analytics for anomalous lateral movement or credential harvesting patterns.
  • Harden Citrix devices against CVE‑2025‑5777 and enforce strict access controls on edge devices (Ivanti, Cisco).
  • Separate access broker activities via network segmentation and privileged access management.
  • Create intrusion detection rules to flag communication with known ShadowPad C&C IPs.

Suggested Tags

APT
Earth Naga
Earth Estries
China-nexus
Generative AI attack
AI-driven reconnaissance
Zero-day exploitation
Spearphishing
Microsoft Graph C2
Proxy tunneling
Espionage
AccessBroker
CriticalSectorTargets
CrossBorderCollaboration

Confidence Assessment

The evidence for Earth Naga’s capabilities and operational behaviors is drawn from multiple independent intelligence reports, providing moderate to high confidence in the identified tactics, techniques, and toolset. However, gaps remain regarding precise attribution, exact timelines of activity, and the full extent of collaboration with Earth Estries. Continuous intelligence updates and telemetry correlation are required to refine threat assessment and validate emerging campaign patterns.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 11 Filename 8 URL 1

References

  1. blog.talosintelligence.com — Cited by web research for: NosyDoor
  2. www.trendmicro.com — Cited by web research for: Flax Typhoon
  3. www.trendmicro.com — Cited by web research for: phishing
  4. malpedia.caad.fkie.fraunhofer.de — Cited by web research for: curl

Intel Summary

7

Techniques

53

Tools

0

Campaigns

40

IOCs

0

Observed Data

5

Tactics

Tags

Ransomware
APT
Backdoor / C2
Government Targeting
espionage
government
military
APAC
NATO
Earth Naga
Earth Estries
China-nexus
Generative AI attack
AI-driven reconnaissance
Zero-day exploitation
Spearphishing
Microsoft Graph C2
Proxy tunneling
Espionage
AccessBroker
CriticalSectorTargets
CrossBorderCollaboration

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.