Chinese Earth Krahang hackers breach 70 orgs in 23 countries
ID: f3a803e0-3c52-5802-b816-ce409f952fd3
STIX ID: report--f3a803e0-3c52-5802-b816-ce409f952fd3
Feed Name: Bleeping Computer
Trend Micro documents a long-running (since early 2022) APT campaign by 'Earth Krahang' that has breached 70 organizations and targeted 116 in 45 countries—principally government entities including foreign ministries—using exploited internet-facing vulnerabilities (e.g., CVE-2023-32315, CVE-2022-21587), spear-phishing, webshells, VPNs on compromised hosts, and backdoors (XDealer, RESHELL, Cobalt Strike) to perform reconnaissance, credential brute-forcing, email exfiltration, lateral movement, and espionage; IoCs are published separately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
