Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors shadow-earth-066, earth dahu

shadow-earth-066, earth dahu

TLP:CLEAR
Active

Also known as: tracked as

Description

Two Russia-aligned campaigns continue exploiting CVE-2025-8088, a WinRAR path traversal vulnerability patched in July 2025, against Ukrainian organizations through April 2026. SHADOW-EARTH-066 deploys an evolved GIFTEDCROOK information stealer using in-memory DLL loading via direct NT system calls, harvesting browser credentials, session cookies, and documents across 35 file extensions before self-deleting. Earth Dahu employs an HTA-based infection chain delivering espionage modules through Cloudflare Workers infrastructure. Both campaigns leverage the same CVE-2025-8088 exploit but use distinct tooling: SHADOW-EARTH-066 relies on compiled C++ with RC4-encrypted C&C communication, while Earth Dahu uses script-based approaches with Dynamic DNS. The persistent exploitation nearly a year post-patch demonstrates how unmanaged software lacking centralized update mechanisms creates enduring attack surfaces that threat actors deliberately target.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Mining

Targeted Countries / Regions

Ukraine

AI Analysis

· 1 week ago

Executive Summary

Shadow-Earth-066 and Earth Dahu are Russia-aligned cyber threat actors targeting Ukrainian government and defense sectors using CVE-2025-8088, a WinRAR path traversal vulnerability. Their campaigns feature advanced information-stealing tools and persistent exploitation techniques despite patch availability. The actors demonstrate high sophistication in tool development and exploit persistence.

Goals & Targeting

These actors appear to have a strategic focus on targeting乌克兰's government and defense sectors, likely to support broader Russian geopolitical objectives or to facilitate espionage activities. Their selection of Ukrainian organizations suggests an intent to gain access to sensitive information, disrupt national security, and potentially influence ongoing conflicts in the region.

Enhanced Description

Two sophisticated cyber threat actors, Shadow-Earth-066 and Earth Dahu, have been observed leveraging the CVE-2025-8088 WinRAR vulnerability to target Ukrainian organizations in an ongoing campaign. Shadow-Earth-066 deploys an evolved GIFTEDCROOK information stealer that employs in-memory DLL loading via NT system calls to harvest browser credentials, session cookies, and documents across 35 file extensions before self-deleting. In contrast, Earth Dahu utilizes an HTA-based infection chain to deliver espionage modules through Cloudflare Workers infrastructure. Both actors share the CVE-2025-8088 exploit but diverge in their tooling: Shadow-Earth-066 relies on compiled C++ with RC4-encrypted command and control communication, while Earth Dahu adopts a script-based approach with Dynamic DNS for persistence. The sustained exploitation of this vulnerability for nearly a year post-patch underscores the risks posed by unmanaged software lacking centralized update mechanisms, which create persistent attack surfaces that threat actors can exploit over extended periods. This activity aligns with Russia's historical playbook of targeting critical infrastructure and government entities in Ukraine to disrupt operations and gather strategic intelligence.

Key Capabilities

  • Exploitation of CVE-2025-8088
  • In-memory DLL loading via NT system calls
  • GIFTEDCROOK information stealer deployment
  • Cloudflare Workers infrastructure exploitation
  • RC4-encrypted C&C communication
  • Dynamic DNS usage for persistence
  • HTA-based infection chain

MITRE ATT&CK Tactics

Credential Access
Exfiltration
Persistence
Defense Evasion
Lateral Movement
Discovery

ATT&CK Techniques

T1566.001
T1218
T1071.001
T1078
T1485
T1394

Software / Tooling

GIFTEDCROOK
Cloudflare Workers
HTA files
RC4 encryption
Compiled C++ tools
Dynamic DNS

Campaigns & Victims

Both Shadow-Earth-066 and Earth Dahu have demonstrated a persistent attack strategy, focusing on the same vulnerability for over a year. Their campaigns highlight the importance of patch management and software update mechanisms in defending against such threats. Notable operations include targeted attacks against Ukrainian government and defense organizations from April 2025 through mid-2026.

IOC Patterns

  • Network traffic associated with Cloudflare Workers infrastructure
  • In-memory DLL loading via NT system calls
  • Exploitation of CVE-2025-8088 in WinRAR files
  • Spear-phishing emails with malicious HTA files or Office documents
  • Dynamic DNS domain generation activity
  • Signs of RC4-encrypted command and control traffic

Recommended Actions

  • Patch all instances of software utilizing the CVE-2025-8088 vulnerability as soon as possible.
  • Monitor for signs of HTA file execution or suspicious in-memory DLL activity on endpoints.
  • Implement logging and monitoring for network traffic to Cloudflare Workers infrastructure and Dynamic DNS domains.
  • Enhance patch management processes to ensure timely updates across all systems, particularly for high-risk vulnerabilities.
  • Use YARA rules or other signature-based detection to identify potential GIFTEDCROOK-related activity.

Suggested Tags

APT
Espionage
Ukraine
Government Targeting
Russia-aligned

Confidence Assessment

High confidence in the targeting patterns and technical details, as several independent reports document similar campaign activities. The actors' motivations and exact operational structure remain less clear, though their activity strongly suggests ties to Russian cyber espionage efforts.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

1

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Backdoor / C2
Espionage
Ukraine
Government Targeting
Russia-aligned

Details

Type
Unknown
Confidence
55%
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.