The Espionage Toolkit: A Closer Look at its Advanced Techniques
Earth Alux, a China-linked APT group, is actively conducting cyberespionage attacks against key sectors in the APAC and Latin American regions. The group exploits vulnerable services in exposed servers to gain initial access and deploys web shells like GODZILLA. Their primary backdoor, VARGEIT, is used alongside COBEACON for various stages of attack. Earth Alux employs advanced techniques such as DLL side-loading, anti-API hooking, and execution guardrails. They utilize tools like RAILLOAD and RAILSETTER for persistence and evasion. The group's capabilities include system information collection, file manipulation, command execution, and tool injection via mspaint processes. Earth Alux targets industries such as government, technology, logistics, and manufacturing, demonstrating a strategic focus on high-value information across different sectors.
Pulse ID: 67ea7b3862f607c0d857f9d8
Pulse Link: https://otx.alienvault.com/pulse/67ea7b3862f607c0d857f9d8
Pulse Author: AlienVault
Created: 2025-03-31 11:23:36
Be advised, this data is unverified and should be considered preliminary. Always do further verification.