logo

Earth Kasha’s Campaign Exploiting Fortinet Vulnerability (Campaign)

ID: 28175a68-0c20-5c24-a9f6-a034d107e2aa

STIX ID: report--28175a68-0c20-5c24-a9f6-a034d107e2aa

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2024-11-19

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

Earth Kasha, an actor active since 2019 and linked to the broader APT10 umbrella, launched a 2023 campaign targeting Japan, Taiwan, and India by exploiting Fortinet CVE-2023-27997 to gain access. The campaign uses DLL side-loading, phishing, credential theft and deploys LODEINFO, NOOPDOOR, MirrorStealer and Cobalt Strike for persistence, credential exfiltration, and data theft; overlaps with other China-linked groups suggest possible 0-day sharing or third-party access brokers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.