Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Wendigo

Description

Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and universities in Taiwan — since May 2019, aiming to exfiltrate emails from targeted organizations via the injection of JavaScript backdoors to a webmail system that is widely used in Taiwan. The threat actor also sent spear-phishing emails embedded with malicious links to multiple individuals, including politicians and activists, who support movements in Tibet, the Uyghur region, or Hong Kong.

Goals & Targeting

Targeted Sectors

Government
Education

AI Analysis

· 1 week ago

Executive Summary

Earth Wendigo, a suspected state-sponsored threat actor originating from China, has been actively targeting government and educational institutions in Taiwan since May 2019. The group employs sophisticated techniques including spear-phishing campaigns and JavaScript-based backdoor injections to gain unauthorized access to webmail systems, aiming to exfiltrate sensitive emails for potential espionage purposes.

Goals & Targeting

Earth Wendigo's primary objectives appear to be intelligence collection and espionage, particularly targeting individuals and organizations involved in politically sensitive issues. Their focus on Taiwan, along with their interest in movements related to Tibet, Uyghur regions, and Hong Kong, indicates possible state-sponsored activities aimed at gathering information that could influence China's geopolitical strategies or undermine opposition groups.

Enhanced Description

Earth Wendigo is a cyber threat actor identified as originating from China, specifically targeting government organizations, research institutions, and universities in Taiwan. Since their first appearance in May 2019, their primary method of attack involves the injection of JavaScript backdoors into webmail systems widely used within Taiwan. This technique allows them to compromise email accounts and exfiltrate sensitive communications. Additionally, Earth Wendigo has engaged in spear-phishing campaigns, sending malicious links embedded within emails to individuals associated with political movements in Tibet, the Uyghur region, or Hong Kong. These targeting patterns suggest a strategic focus on获取政治相关的敏感信息 or disrupting activities aligned with specific Chinese government interests.

Key Capabilities

  • Injection of JavaScript backdoors into webmail systems
  • Spear-phishing campaigns with embedded malicious links
  • Compromise of email accounts for data exfiltration
  • Potential use of custom malware frameworks

MITRE ATT&CK Tactics

Initial Access
Execution

ATT&CK Techniques

T1067.002
T1184.001
T1091.001

Software / Tooling

Custom JavaScript backdoor
Spear-phishing toolset

Campaigns & Victims

Earth Wendigo has demonstrated consistent activity since 2019, primarily targeting Taiwan's government and education sectors. Campaign patterns include prolonged email compromise operations and targeted phishing attempts against specific individuals. Their operational tempo suggests a structured approach to long-term intelligence gathering, possibly with an aim to remain undetected for extended periods.

IOC Patterns

  • Spear-phishing emails containing malicious links
  • Injected JavaScript in webmail systems
  • Malicious scripts targeting email exfiltration

Recommended Actions

  • Implement robust anti-spam and phishing filters to detect malicious emails
  • Monitor for script injection attempts on webmail platforms
  • Conduct regular security audits of educational and government IT infrastructure
  • Educate users on spotting phishing attempts and suspicious emails

Suggested Tags

APT
espionage
government-targeted
education-sector
political-motivation

Confidence Assessment

The analysis of Earth Wendigo is based on available threat intelligence, which provides moderate confidence in their origin and primary TTPs. The data gaps include specific tools used beyond JavaScript injections, exact campaign timelines, and the full extent of their targeting in other regions.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
espionage
government-targeted
education-sector
political-motivation

Details

Type
Unknown
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.