Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Longzhi

Also known as: SnakeCharmer

Description

Earth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Execution Options (IFEO), a new denial-of-service (DoS) technique to disable security software.

AI Analysis

· 1 week ago

Executive Summary

Earth Longzhi, also known as SnakeCharmer, appears to be a subgroup associated with APT41. It primarily targets organizations in Taiwan, Thailand, the Philippines, and Fiji using a novel denial-of-service (DoS) technique involving Image File Execution Options (IFEO), referred to as 'stack rumbling.' This group demonstrates intermediate sophistication with a focus on disrupting security software through innovative attack methods.

Goals & Targeting

The strategic goals of Earth Longzhi likely align with those of APT41, which has been linked to espionage and sabotage activities. The targeting of regions such as Taiwan, Thailand, the Philippines, and Fiji suggests a focus on regional stability or economic interests. The use of DoS techniques indicates an intent to disrupt or degrade the effectiveness of security software, possibly to facilitate access to targeted systems or to create conditions favorable for further attacks.

Enhanced Description

Earth Longzhi is a subgroup within the broader APT41 threat group, which has previously been associated with state-sponsored activities. The subgroup operates with a specific regional focus, targeting industries and organizations in Taiwan, Thailand, the Philippines, and Fiji. Its primary tactic involves 'stack rumbling,' a form of denial-of-service (DoS) attack that leverages Image File Execution Options (IFEO). This technique disrupts the execution of security software by manipulating stack operations, potentially leading to system instability or service interruptions. While specific campaign details are limited, the group's activities suggest a focus on disrupting or bypassing security measures to achieve its objectives.

Key Capabilities

  • Intermediate-level cyber capabilities
  • DoS attacks with novel techniques
  • Manipulation of Image File Execution Options (IFEO)
  • Targeted regional campaigns
  • Potential ties to APT41

MITRE ATT&CK Tactics

Disruption
Persistence

ATT&CK Techniques

T1059.003
T1566.001

Software / Tooling

Custom DoS exploit tools
IFEO manipulation tools

Campaigns & Victims

Earth Longzhi's campaign patterns are not extensively documented, but its use of 'stack rumbling' suggests an emphasis on innovative attack methods. The group appears to operate with a regional focus, targeting specific industries in Southeast Asia and the Pacific. Past operations indicate a preference for disrupting security infrastructure rather than immediate data exfiltration, possibly as a precursor to more comprehensive attacks.

IOC Patterns

  • Spear-phishing-like activity targeting specific regions
  • IFEO registry manipulation
  • Unusual process behavior related to stack operations

Recommended Actions

  • Implement robust monitoring of IFEO settings and process behavior
  • Enhance detection mechanisms for novel DoS techniques
  • Conduct regular security assessments in targeted sectors
  • Apply patches for known vulnerabilities related to image file execution
  • Educate employees on regional geopolitical threats

Suggested Tags

APT41 subgroup
State-sponsored activity
Denial-of-Service (DoS)
Regional targeting
Stack manipulation

Confidence Assessment

Confidence in the details of Earth Longzhi's activities is low due to limited available information. While its association with APT41 and use of IFEO-based DoS attacks provide some context, further intelligence is needed to fully characterize its capabilities, campaign patterns, and precise motivations.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT41 subgroup
State-sponsored activity
Denial-of-Service (DoS)
Regional targeting
Stack manipulation

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.