216.73.217.80

Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions

· Published 03/12/2024 15:34 · Modified 03/12/2024 16:24

Export JSON

Essential information

Published
03/12/2024 15:34
Modified
03/12/2024 16:24
Tags
2024-12-03 chinese apt crowdoor demodex government masol rat snappybee sparrowdoor telecommunications
Related entities
8 vulnerabilities (cve), 57 observables, 1 intrusion sets (apt), 20 techniques (mitre), 6 malware, 18 others

Description

Earth Estries, a group, has been aggressively targeting critical sectors globally since 2023. The group employs advanced techniques and multiple backdoors, including GHOSTSPIDER, , and , to compromise organizations in , , and other industries across various countries. Their sophisticated attacks exploit server vulnerabilities for initial access and use living-off-the-land binaries for lateral movement. Earth Estries has successfully infiltrated over 20 organizations, demonstrating a complex C&C infrastructure and possible shared tools with other groups. The group's operations involve long-term espionage activities, targeting not only critical services but also vendor networks to facilitate broader access.

External references