Beijing-backed cyberspies attacked 70+ orgs across 23 countries
ID: 51a62436-f55e-5917-940c-60cfaa6143bc
STIX ID: report--51a62436-f55e-5917-940c-60cfaa6143bc
Feed Name: The Register (Security)
Trend Micro attributes a sustained China-linked espionage campaign named Earth Krahang to a state-backed actor that has compromised at least 70 organizations and targeted 116+ victims—mostly government entities—across 23 countries. The group exploits internet-facing servers (including CVE-2023-32315 and CVE-2022-21587), performs brute-force and phishing operations, steals credentials and emails, and deploys custom backdoors (RESHELL and XDealer), SoftEther VPN for lateral movement, and occasionally Cobalt Strike; Trend Micro publishes IOCs and recommends patching, phishing training, and validation of attachments/links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
