Earth Alux Hackers Use VARGIET Malware to Target Organizations
ID: afd5b316-f418-5123-9347-c21c55d56173
STIX ID: report--afd5b316-f418-5123-9347-c21c55d56173
Feed Name: GBHackers
Earth Alux, a China-linked APT active since 2023, has been using a sophisticated toolkit centered on the VARGEIT multi-stage backdoor—alongside COBEACON, RAILLOAD and RAILSETTER—and employing techniques like DLL sideloading, timestomping and web shells to perform long-term cyberespionage and data exfiltration against government, technology, logistics, manufacturing, telecommunications, IT services and retail organizations across APAC and, more recently, Latin America; defenders are advised to patch systems, monitor for anomalous activity, and deploy EDR solutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
