The Espionage Toolkit: A Closer Look at its Advanced Techniques
Essential information
- Published
- 31/03/2025 11:23
- Modified
- 03/04/2025 15:00
- Tags
- 2025-03-31 apac apt cobeacon cyberespionage dll side-loading godzilla latin america masqloader railload railsetter rsbinject vargeit
- Related entities
- 1 intrusion sets (apt), 16 techniques (mitre), 7 malware, 11 others
Description
Earth Alux, a China-linked APT group, is actively conducting cyberespionage attacks against key sectors in the APAC and Latin American regions. The group exploits vulnerable services in exposed servers to gain initial access and deploys web shells like GODZILLA. Their primary backdoor, VARGEIT, is used alongside COBEACON for various stages of attack. Earth Alux employs advanced techniques such as DLL side-loading, anti-API hooking, and execution guardrails. They utilize tools like RAILLOAD and RAILSETTER for persistence and evasion. The group's capabilities include system information collection, file manipulation, command execution, and tool injection via mspaint processes. Earth Alux targets industries such as government, technology, logistics, and manufacturing, demonstrating a strategic focus on high-value information across different sectors.