216.73.216.6

MOONSHINE Exploit Kit and DarkNimbus Backdoor Enabling Earth Minotaur's Multi-Platform Attacks

· Published 05/12/2024 07:31 · Modified 05/12/2024 10:24

Export JSON

Essential information

Published
05/12/2024 07:31
Modified
05/12/2024 10:24
Tags
2024-12-05 android backdoor darknimbus exploit-kit moonshine shadowpad
Related entities
1 intrusion sets (apt), 18 techniques (mitre), 4 malware, 1 others

Description

Earth Minotaur, a threat actor targeting Tibetan and Uyghur communities, utilizes the exploit kit to compromise devices and install the . The exploit kit targets vulnerabilities in instant messaging apps, particularly WeChat, and has been updated with new exploits since 2019. , an unreported with a Windows version, allows for comprehensive surveillance. The attack chain involves social engineering tactics, exploiting Chromium-based vulnerabilities, and implanting a trojanized XWalk browser core. The supports various data collection and device control features. Earth Minotaur appears to be a distinct intrusion set from previously reported groups, though connections to other Chinese operations are noted.

External references