Earth Baku campaign (Campaign)
ID: b6d9fc4c-71e5-5fc5-9709-2627e7a647ea
STIX ID: report--b6d9fc4c-71e5-5fc5-9709-2627e7a647ea
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2024-08-09
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Earth Baku (linked to APT41) has expanded operations beyond the Indo‑Pacific into Europe, the Middle East, and Africa, exploiting public-facing IIS servers to deploy advanced malware including the Godzilla webshell, StealthVector and StealthReacher loaders, and the SneakCross backdoor. The group uses obfuscation and encryption in loaders, leverages Google services for C2, maintains persistence with tools like Rakshasa and Tailscale, and exfiltrates data via MEGAcmd, reflecting a modular and sophisticated threat posture.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
