Chinese APT 'Earth Krahang' Compromises 48 Gov't Orgs on 5 Continents
ID: 73a95f30-15e0-50ad-8017-4909538df03a
STIX ID: report--73a95f30-15e0-50ad-8017-4909538df03a
Feed Name: Dark Reading
Earth Krahang is a Chinese-linked espionage group that has successfully compromised at least 70 organizations across dozens of countries—predominantly government entities—by leveraging open-source scanning tools, one-day/known vulnerabilities (e.g., CVE-2023-32315, CVE-2022-21587), brute-force credential harvesting, and social-engineered spear-phishing via hijacked legitimate email accounts; post-compromise activity includes deploying backdoors (RESHELL, XDealer), using Cobalt Strike and legacy implants (PlugX, ShadowPad), and exfiltrating data, prompting recommendations to patch systems, enhance email defenses, monitor for anomalous access and network traffic, and apply network segmentation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
