logo

Earth Alux Hackers Use VARGIET Malware to Target Organizations

ID: afd5b316-f418-5123-9347-c21c55d56173

STIX ID: report--afd5b316-f418-5123-9347-c21c55d56173

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2025-03-31

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Earth Alux, a China-linked APT active since 2023, has been using a sophisticated toolkit centered on the VARGEIT multi-stage backdoor—alongside COBEACON, RAILLOAD and RAILSETTER—and employing techniques like DLL sideloading, timestomping and web shells to perform long-term cyberespionage and data exfiltration against government, technology, logistics, manufacturing, telecommunications, IT services and retail organizations across APAC and, more recently, Latin America; defenders are advised to patch systems, monitor for anomalous activity, and deploy EDR solutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.