logo

Earth Alux Hackers Deploy VARGIET Malware in Targeted Organizational Attacks

ID: 325c3379-a9ae-5f4b-be1d-2e6a5abd2203

STIX ID: report--325c3379-a9ae-5f4b-be1d-2e6a5abd2203

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-13

Author: Mandvi

...
...

**Executive Summary:** Earth Alux is a China-linked advanced persistent threat that has used the multi-stage VARGEIT backdoor, along with RAILLOAD and RAILSETTER, to conduct targeted cyberespionage against government, technology, logistics, manufacturing, telecommunications, and retail organizations across APAC and expanding into Latin America; the report highlights DLL side-loading, process injection (e.g., into mspaint.exe), multi-channel encrypted command-and-control (HTTP, reverse TCP/UDP, Microsoft Graph), and advanced persistence and evasion techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.