Earth Kasha’s Campaign Exploiting Fortinet Vulnerability (Campaign)
ID: 28175a68-0c20-5c24-a9f6-a034d107e2aa
STIX ID: report--28175a68-0c20-5c24-a9f6-a034d107e2aa
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-11-19
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Earth Kasha, an actor active since 2019 and linked to the broader APT10 umbrella, launched a 2023 campaign targeting Japan, Taiwan, and India by exploiting Fortinet CVE-2023-27997 to gain access. The campaign uses DLL side-loading, phishing, credential theft and deploys LODEINFO, NOOPDOOR, MirrorStealer and Cobalt Strike for persistence, credential exfiltration, and data theft; overlaps with other China-linked groups suggest possible 0-day sharing or third-party access brokers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
