logo

Earth Alux Hackers Employ VARGIET Malware to Attack Organizations

ID: 0d05a657-50dd-546e-9ba6-e6b83807c6d5

STIX ID: report--0d05a657-50dd-546e-9ba6-e6b83807c6d5

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2025-03-31

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Earth Alux is a China-linked APT active since Q2 2023 that exploits vulnerable exposed services to deploy web shells (e.g., GODZILLA) and multi-channel backdoors (VARGEIT, COBEACON), targeting government, technology, logistics, manufacturing, telecommunications, IT services, and retail across Asia‑Pacific and Latin America; notable techniques include a novel mspaint.exe code-injection method (avoiding disk artifacts), use of Outlook/Graph API for covert C2, and exfiltration to attacker-controlled cloud storage.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.