logo

Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions

ID: d8b27e62-e048-5d2e-957a-d1d7cd89ae4b

STIX ID: report--d8b27e62-e048-5d2e-957a-d1d7cd89ae4b

Feed Name: TrendAI Security Blog

Threat Score
88/100

Date Published: 2026-01-01

Date Updated: 2026-08-14

...
...

TrendAI Vision One reports that the Earth Estries APT has conducted prolonged, sophisticated espionage campaigns since 2020 against telecommunications, government, and related service providers across multiple regions; the report details initial access via public-facing server vulnerabilities (including multiple CVEs and ProxyLogon), the use of living-off-the-land tools and custom backdoors/rootkits (DEMODEX, GHOSTSPIDER, SNAPPYBEE, MASOL RAT), C2 infrastructure analysis, victimology spanning 20+ organizations in numerous countries, and operational attribution/overlap with other Chinese APT toolsets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.