Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Kitsune

Description

Earth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and use various tactics, such as compromising websites and employing social engineering, to distribute self-developed backdoors. Earth Kitsune demonstrates technical proficiency and continuously evolves their tools, tactics, and procedures. They have been associated with malware such as WhiskerSpy and SLUB.

AI Analysis

· 2 months ago

Executive Summary

Earth Kitsune is an advanced persistent threat actor that has been active since at least 2019, primarily targeting individuals interested in North Korea with sophisticated tactics, including social engineering and custom backdoors. Their primary goal appears to be intelligence gathering, leveraging their technical proficiency to evolve their tools and procedures. Continuous monitoring and adaptation are necessary to counter their evolving threats.

Goals & Targeting

Earth Kitsune's strategic objectives appear to be centered around intelligence gathering, with a particular focus on individuals interested in North Korea. Their targeting profile suggests a deliberate approach, aiming to exploit vulnerabilities in human factors and technology to achieve access to sensitive information. The typical victims of Earth Kitsune are likely to be individuals or organizations with interests or ties to North Korea, indicating a tailored approach to their operations.

Enhanced Description

Given the nature of their targets and the methods they employ, Earth Kitsune's activities are of significant concern to both government and private sector entities involved in or interested in North Korean affairs. The group's continuous evolution and adaptation of their TTPs necessitate a vigilant and proactive approach to cybersecurity from potential targets, emphasizing the importance of threat intelligence, enhanced security measures, and user awareness training.

Key Capabilities

  • Social Engineering
  • Custom Malware Development
  • Web Compromise
  • Backdoor Installation
  • Continuous Evolution of TTPs

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion

ATT&CK Techniques

T1587.001
T1684
T1588.001
T1059.003
T1055
T1566.001

Software / Tooling

WhiskerSpy
SLUB
Custom RAT

Campaigns & Victims

Earth Kitsune's campaign patterns are marked by a strategic and targeted approach, selecting victims based on their interests in North Korea. Their operational tempo is characterized by continuous evolution and adaptation, suggesting a sophisticated and well-resourced organization. Notable past operations include the distribution of custom backdoors through compromised websites and social engineering tactics, highlighting the group's ability to innovate and adjust their TTPs to evade detection.

IOC Patterns

  • Spear-phishing with macro-laced Office documents
  • C2 over DNS using fast-flux
  • Staging infrastructure on bulletproof hosting
  • Custom backdoor installation via compromised websites

Recommended Actions

  • Enhance User Awareness Training
  • Implement Advanced Threat Detection Systems
  • Conduct Regular Network and System Audits
  • Utilize Secure Communication Channels
  • Keep All Software Up-to-Date

Suggested Tags

APT
Espionage
Custom Malware
Social Engineering

Confidence Assessment

The confidence level in the available data regarding Earth Kitsune is moderate to high, owing to the group's documented activities and associations with specific malware families. However, there are information gaps regarding their exact motivations, the full scope of their capabilities, and their organizational structure, which would require further intelligence gathering to fully assess and counter the threat they pose.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Ransomware
APT
Critical Infrastructure
Backdoor / C2
Espionage
Custom Malware
Social Engineering

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.