Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions
ID: d8b27e62-e048-5d2e-957a-d1d7cd89ae4b
STIX ID: report--d8b27e62-e048-5d2e-957a-d1d7cd89ae4b
Feed Name: TrendAI Security Blog
TrendAI Vision One reports that the Earth Estries APT has conducted prolonged, sophisticated espionage campaigns since 2020 against telecommunications, government, and related service providers across multiple regions; the report details initial access via public-facing server vulnerabilities (including multiple CVEs and ProxyLogon), the use of living-off-the-land tools and custom backdoors/rootkits (DEMODEX, GHOSTSPIDER, SNAPPYBEE, MASOL RAT), C2 infrastructure analysis, victimology spanning 20+ organizations in numerous countries, and operational attribution/overlap with other Chinese APT toolsets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
