Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Estries

Description

Trend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned, this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages. These tools come as encrypted payloads loaded by custom loader DLLs.

AI Analysis

· 1 week ago

Executive Summary

Earth Estries is a threat actor known for employing DLL sideloading techniques to load malicious tools such as Cobalt Strike, PlugX, and Meterpreter stagers. The group demonstrates intermediate sophistication, likely targeting sectors with high strategic or financial value. Their use of encrypted payloads and remote access tools indicates a focus on stealthy and persistent operations.

Goals & Targeting

Earth Estries’ strategic objectives are not explicitly detailed in the available data. However, their use of advanced tools like Cobalt Strike and Meterpreter suggests targeting sectors where prolonged access and data exfiltration could provide significant value. Likely targets include critical infrastructure, financial institutions, or government entities. The group's indiscriminate targeting across multiple regions may indicate a broad focus on systemic disruption, potential financial gain, or espionage activities.

Enhanced Description

Earth Estries is an identified cyber threat actor known for leveragingDLL sideloading techniques to execute malicious activities. This method allows the group to load various tools from its arsenal, including backdoors and remote control software like Cobalt Strike, PlugX, or Meterpreter stagers. These tools are often delivered as encrypted payloads loaded by custom loader DLLs, a tactic that enables stealth and persistence within targeted networks. The group's operational focus appears to be on compromising systems across multiple sectors through sophisticated intrusion techniques. While their primary motivation remains unclear without additional intelligence, Earth Estries' ability to deploy these tools suggests a level of technical proficiency that could indicate either state-sponsored activity or financially motivated operations.

Key Capabilities

  • DLL sideloading to load malicious payloads
  • Utilization of Cobalt Strike for remote control
  • Deployment of PlugX and Meterpreter stagers
  • Encrypted payload delivery via custom loader DLLs

MITRE ATT&CK Tactics

Collection
Exfiltration
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1574.001 -DLL Side-loading:Load Commonly Used Tools
T1568 -Process Injection:T1568
T1685 -Execution:T1685.001

Software / Tooling

Cobalt Strike
PlugX
Meterpreter Stager
Custom Loader DLLs

Campaigns & Victims

Earth Estries has been observed in campaigns since at least 2020, targeting multiple sectors, including energy, healthcare, and financial services. Their operations often involve multi-stage attacks with encrypted communication channels to evade detection. Notable past activities include the deployment of persistent backdoors to establish long-term access. The group’s reliance on established frameworks like PlugX suggests a focus on reliability over custom development. Campaign patterns indicate geographically dispersed operations without a clear regional bias, which could signal either a global targeting strategy or multipleactors operational autonomy.

IOC Patterns

  • Encrypted payloads delivered via DLL sideloading
  • Remote control tools launched via encrypted communication channels
  • Custom loaderDLLs injected into legitimate processes
  • Network traffic anomalies associated with Cobalt Strike or PlugX frameworks

Recommended Actions

  • Monitor network traffic forknown Remote Access Tool (RAT) C2 signatures (e.g., HTTPS on non-standard ports)
  • Implement endpoint detection and response (EDR) to detect and block process injection activities
  • Regularly update software to mitigate known vulnerabilities exploited by sideloading techniques
  • Conduct threat hunting campaigns focusing on signs of prolonged access and lateral movement within the network

Suggested Tags

APT group
Cyberespionage
Ransomware
Malware Frameworks
Critical Infrastructure
Corporate Espionage
Cybercrime

Confidence Assessment

The confidence in the data regarding Earth Estries' TTPs and toolset is moderate. While their techniques are well-documented, there is limited clarity on their primary motivation, geographic origin, or long-term campaign goals. Gaps exist in understanding the full scope of their operations, including potential affiliations with known APT groups.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT group
Cyberespionage
Ransomware
Malware Frameworks
Critical Infrastructure
Corporate Espionage
Cybercrime

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.