China's 'Earth Baxia' Spies Exploit Geoserver to Target APAC Orgs
ID: 5e429d99-d27b-540c-adbf-064921a95db2
STIX ID: report--5e429d99-d27b-540c-adbf-064921a95db2
Feed Name: Dark Reading
Threat Score
Trend Micro warns of a China-linked APT dubbed Earth Baxia conducting espionage across the Asia-Pacific by spear-phishing and exploiting GeoServer (CVE-2024-36401) to install Cobalt Strike or a custom EagleDoor backdoor; targets include government, military, energy, and telecom sectors and the group leverages techniques such as GrimResource and AppDomainManager injection with infrastructure largely hosted in China.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
