Earth Alux Hackers Deploy VARGIET Malware in Targeted Organizational Attacks
ID: 325c3379-a9ae-5f4b-be1d-2e6a5abd2203
STIX ID: report--325c3379-a9ae-5f4b-be1d-2e6a5abd2203
Feed Name: Cyber Press
**Executive Summary:** Earth Alux is a China-linked advanced persistent threat that has used the multi-stage VARGEIT backdoor, along with RAILLOAD and RAILSETTER, to conduct targeted cyberespionage against government, technology, logistics, manufacturing, telecommunications, and retail organizations across APAC and expanding into Latin America; the report highlights DLL side-loading, process injection (e.g., into mspaint.exe), multi-channel encrypted command-and-control (HTTP, reverse TCP/UDP, Microsoft Graph), and advanced persistence and evasion techniques.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
