⤷ Title: Earth Alux APT Group: Unveiling Its Espionage Toolkit
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 01:05:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cobeacon #Earth Alux #Earth Alux APT #RAILSETTER #VARGEIT backdoor
════════════════════════
𐀪 Author: do son
════════════════════════
ⴵ Time: Tue, 01 Apr 2025 01:05:32 +0000
════════════════════════
⌗ Tags: #Cyber Security #Cobeacon #Earth Alux #Earth Alux APT #RAILSETTER #VARGEIT backdoor
Daily CyberSecurity
Earth Alux APT Group: Unveiling Its Espionage Toolkit
Explore the capabilities of Earth Alux, an APT group using intricate tools for cyber-espionage in strategic sectors globally.
⤷ Title: BPFDoor Backdoor Used in Asia, Middle East Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:12:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #backdoor #BPF #BPFDoor #Cyberespionage #Earth Bluecrow #malware #network_security #Red Menshen
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 16 Apr 2025 00:12:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #APT #backdoor #BPF #BPFDoor #Cyberespionage #Earth Bluecrow #malware #network_security #Red Menshen
Daily CyberSecurity
BPFDoor Backdoor Used in Asia, Middle East Cyberespionage
Trend Micro uncovers BPFDoor backdoor used in cyberespionage across Asia and the Middle East, attributing it to the Red Menshen APT group
⤷ Title: Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 22 Apr 2025 00:33:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #App_V #APT #ASEC #cybersecurity #DLL injection #Earth Preta #Lazarus Group #malware injection #mavinject.exe #signed binary abuse #Windows Security
Daily CyberSecurity
Legitimate Windows Tool Abused: mavinject.exe Used for Stealthy DLL Injection by Threat Actors
Threat actors abuse Microsoft’s mavinject.exe to inject malicious DLLs into trusted processes, evading detection in stealthy APT campaigns.
⤷ Title: Earth Kurma APT Targets Southeast Asia with Stealthy Cyberespionage
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #Earth Kurma #Government Hacking #KRNRAT #MORIYA #Rootkits #SIMPOBOXSPY #Southeast Asia #Trend Research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 29 Apr 2025 00:10:03 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #Cyberespionage #Earth Kurma #Government Hacking #KRNRAT #MORIYA #Rootkits #SIMPOBOXSPY #Southeast Asia #Trend Research
Daily CyberSecurity
Earth Kurma APT Targets Southeast Asia with Stealthy Cyberespionage
Earth Kurma APT campaign targets Southeast Asian governments and telecoms using rootkits, loaders, and cloud services to steal sensitive data.
⤷ Title: Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:03:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ANEL #APT10 #cyber_espionage #DNS_over_HTTPS #Earth Kasha #Japan #NOOPDOOR #SharpHide #spear_phishing #Taiwan #Trend Micro
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 01 May 2025 00:03:42 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #ANEL #APT10 #cyber_espionage #DNS_over_HTTPS #Earth Kasha #Japan #NOOPDOOR #SharpHide #spear_phishing #Taiwan #Trend Micro
Daily CyberSecurity
Earth Kasha Refines Spear-Phishing Tactics in Espionage Campaign Targeting Taiwan and Japan
Earth Kasha targets Taiwan and Japan in a March 2025 spear-phishing campaign using ANEL and NOOPDOOR backdoors for stealthy cyber espionage.
⤷ Title: Eyes on Earth: The GEOINT OSINT Blog
════════════════════════
𐀪 Author: Intelligent rose
════════════════════════
ⴵ Time: Fri, 02 May 2025 19:39:25 GMT
════════════════════════
⌗ Tags: #osint #earth #cybersecurity #intelligence #geoint
════════════════════════
𐀪 Author: Intelligent rose
════════════════════════
ⴵ Time: Fri, 02 May 2025 19:39:25 GMT
════════════════════════
⌗ Tags: #osint #earth #cybersecurity #intelligence #geoint
Medium
Eyes on Earth: The GEOINT OSINT Blog
GEOINT, or Geospatial Intelligence, is a part of OSINT (Open-Source Intelligence) that focuses on information related to locations, maps…
⤷ Title: Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:20:43 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #CLNTEND #CXCLNT #cyber_espionage #Earth Ammit #fiber_based evasion #military cybersecurity #supply chain attack #Taiwan #TIDRONE #Trend Micro #venom
Daily CyberSecurity
Earth Ammit Strikes Drone Supply Chains: VENOM and TIDRONE Campaigns Expose East Asia’s Critical Infrastructure
Earth Ammit’s VENOM and TIDRONE campaigns target Taiwan and South Korea’s drone, military, and satellite sectors via stealthy supply chain attacks.
⤷ Title: Earth Lamia: China-Linked APT Targets Global Industries with Custom Backdoors
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 28 May 2025 00:01:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #backdoor #china #CVE #cyber_espionage #Earth Lamia #malware #PULSEPACK #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 28 May 2025 00:01:21 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #backdoor #china #CVE #cyber_espionage #Earth Lamia #malware #PULSEPACK #sql injection
Daily CyberSecurity
Earth Lamia: China-Linked APT Targets Global Industries with Custom Backdoors
Earth Lamia, a China-linked APT, is targeting critical industries worldwide using SQL injection, CVEs, and custom backdoors like PULSEPACK.
⤷ Title: Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 00:27:20 +0000
════════════════════════
⌗ Tags: #Cyber Security #Malware #APT #China Mobile Tietong #China_aligned threat actors #Cyberespionage #cybersecurity #DLL Sideloading #Earth Lamia #UNC5174 #VELETRIX #VShell
Daily CyberSecurity
Operation DRAGONCLONE: China Mobile Tietong Hit by Advanced APT Attack
Seqrite Labs uncovers Operation DRAGONCLONE, a sophisticated APT campaign targeting China Mobile Tietong with VELETRIX and VShell malware.
⤷ Title: Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 10 Jul 2025 00:11:17 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability Report #ASEC #CoinMiner #cybersecurity #Earth Baxia #Fortinet #GeoServer #GIS #netcat #rce #Remote Code Execution #Trend Micro #Vulnerability #XMRig
Daily CyberSecurity
Ongoing Attacks Exploit GeoServer RCE Flaw (CVE-2024-36401) to Install NetCat and XMRig CoinMiner
GeoServer's RCE flaw (CVE-2024-36401) is actively exploited to deploy NetCat reverse shells and XMRig CoinMiners on Windows/Linux, hijacking resources.