logo

Earth Estries alive and kicking

ID: ff0da4b3-238d-5830-9267-d7465ed44aa4

STIX ID: report--ff0da4b3-238d-5830-9267-d7465ed44aa4

Feed Name: Blaze's Security Blog

Threat Score
75/100

Date Published: 2025-10-27

Date Updated: 2026-04-19

Author: Bart

...
...

The report outlines an Earth Estries (aka Salt Typhoon) campaign abusing a recent WinRAR vulnerability (CVE-2025-8088) to achieve shellcode execution, leveraging fake PDFs, DLL hijacking, and scheduled tasks to deploy payloads and contact external infrastructure. It provides concrete indicators of compromise (hashes, filenames, IP/domain), associated YARA rules, and references for further analysis, enabling detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.