logo

Chinese APT 'Earth Krahang' Compromises 48 Gov't Orgs on 5 Continents

ID: 73a95f30-15e0-50ad-8017-4909538df03a

STIX ID: report--73a95f30-15e0-50ad-8017-4909538df03a

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-03-18

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Earth Krahang is a Chinese-linked espionage group that has successfully compromised at least 70 organizations across dozens of countries—predominantly government entities—by leveraging open-source scanning tools, one-day/known vulnerabilities (e.g., CVE-2023-32315, CVE-2022-21587), brute-force credential harvesting, and social-engineered spear-phishing via hijacked legitimate email accounts; post-compromise activity includes deploying backdoors (RESHELL, XDealer), using Cobalt Strike and legacy implants (PlugX, ShadowPad), and exfiltrating data, prompting recommendations to patch systems, enhance email defenses, monitor for anomalous access and network traffic, and apply network segmentation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.