logo

China's 'Earth Baxia' Spies Exploit Geoserver to Target APAC Orgs

ID: 5e429d99-d27b-540c-adbf-064921a95db2

STIX ID: report--5e429d99-d27b-540c-adbf-064921a95db2

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-09-23

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Trend Micro warns of a China-linked APT dubbed Earth Baxia conducting espionage across the Asia-Pacific by spear-phishing and exploiting GeoServer (CVE-2024-36401) to install Cobalt Strike or a custom EagleDoor backdoor; targets include government, military, energy, and telecom sectors and the group leverages techniques such as GrimResource and AppDomainManager injection with infrastructure largely hosted in China.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.