Trend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned, this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages. These tools come as encrypted payloads loaded by custom loader DLLs.
Executive Summary
Earth Estries is a threat actor known for employing DLL sideloading techniques to load malicious tools such as Cobalt Strike, PlugX, and Meterpreter stagers. The group demonstrates intermediate sophistication, likely targeting sectors with high strategic or financial value. Their use of encrypted payloads and remote access tools indicates a focus on stealthy and persistent operations.
Goals & Targeting
Earth Estries’ strategic objectives are not explicitly detailed in the available data. However, their use of advanced tools like Cobalt Strike and Meterpreter suggests targeting sectors where prolonged access and data exfiltration could provide significant value. Likely targets include critical infrastructure, financial institutions, or government entities. The group's indiscriminate targeting across multiple regions may indicate a broad focus on systemic disruption, potential financial gain, or espionage activities.
Enhanced Description
Earth Estries is an identified cyber threat actor known for leveragingDLL sideloading techniques to execute malicious activities. This method allows the group to load various tools from its arsenal, including backdoors and remote control software like Cobalt Strike, PlugX, or Meterpreter stagers. These tools are often delivered as encrypted payloads loaded by custom loader DLLs, a tactic that enables stealth and persistence within targeted networks. The group's operational focus appears to be on compromising systems across multiple sectors through sophisticated intrusion techniques. While their primary motivation remains unclear without additional intelligence, Earth Estries' ability to deploy these tools suggests a level of technical proficiency that could indicate either state-sponsored activity or financially motivated operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Estries has been observed in campaigns since at least 2020, targeting multiple sectors, including energy, healthcare, and financial services. Their operations often involve multi-stage attacks with encrypted communication channels to evade detection. Notable past activities include the deployment of persistent backdoors to establish long-term access. The group’s reliance on established frameworks like PlugX suggests a focus on reliability over custom development. Campaign patterns indicate geographically dispersed operations without a clear regional bias, which could signal either a global targeting strategy or multipleactors operational autonomy.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the data regarding Earth Estries' TTPs and toolset is moderate. While their techniques are well-documented, there is limited clarity on their primary motivation, geographic origin, or long-term campaign goals. Gaps exist in understanding the full scope of their operations, including potential affiliations with known APT groups.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics