Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and universities in Taiwan — since May 2019, aiming to exfiltrate emails from targeted organizations via the injection of JavaScript backdoors to a webmail system that is widely used in Taiwan. The threat actor also sent spear-phishing emails embedded with malicious links to multiple individuals, including politicians and activists, who support movements in Tibet, the Uyghur region, or Hong Kong.
Targeted Sectors
Executive Summary
Earth Wendigo, a suspected state-sponsored threat actor originating from China, has been actively targeting government and educational institutions in Taiwan since May 2019. The group employs sophisticated techniques including spear-phishing campaigns and JavaScript-based backdoor injections to gain unauthorized access to webmail systems, aiming to exfiltrate sensitive emails for potential espionage purposes.
Goals & Targeting
Earth Wendigo's primary objectives appear to be intelligence collection and espionage, particularly targeting individuals and organizations involved in politically sensitive issues. Their focus on Taiwan, along with their interest in movements related to Tibet, Uyghur regions, and Hong Kong, indicates possible state-sponsored activities aimed at gathering information that could influence China's geopolitical strategies or undermine opposition groups.
Enhanced Description
Earth Wendigo is a cyber threat actor identified as originating from China, specifically targeting government organizations, research institutions, and universities in Taiwan. Since their first appearance in May 2019, their primary method of attack involves the injection of JavaScript backdoors into webmail systems widely used within Taiwan. This technique allows them to compromise email accounts and exfiltrate sensitive communications. Additionally, Earth Wendigo has engaged in spear-phishing campaigns, sending malicious links embedded within emails to individuals associated with political movements in Tibet, the Uyghur region, or Hong Kong. These targeting patterns suggest a strategic focus on获取政治相关的敏感信息 or disrupting activities aligned with specific Chinese government interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Wendigo has demonstrated consistent activity since 2019, primarily targeting Taiwan's government and education sectors. Campaign patterns include prolonged email compromise operations and targeted phishing attempts against specific individuals. Their operational tempo suggests a structured approach to long-term intelligence gathering, possibly with an aim to remain undetected for extended periods.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis of Earth Wendigo is based on available threat intelligence, which provides moderate confidence in their origin and primary TTPs. The data gaps include specific tools used beyond JavaScript injections, exact campaign timelines, and the full extent of their targeting in other regions.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics