Earth Alux Hackers Employ VARGIET Malware to Attack Organizations
ID: 0d05a657-50dd-546e-9ba6-e6b83807c6d5
STIX ID: report--0d05a657-50dd-546e-9ba6-e6b83807c6d5
Feed Name: cybersecurityNews.com
Earth Alux is a China-linked APT active since Q2 2023 that exploits vulnerable exposed services to deploy web shells (e.g., GODZILLA) and multi-channel backdoors (VARGEIT, COBEACON), targeting government, technology, logistics, manufacturing, telecommunications, IT services, and retail across Asia‑Pacific and Latin America; notable techniques include a novel mspaint.exe code-injection method (avoiding disk artifacts), use of Outlook/Graph API for covert C2, and exfiltration to attacker-controlled cloud storage.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
