Read more about the latest research I did with my talented colleague @jaromirhorejsi ! We exposed a previously unreported and new malware family we named KTLVdoor, used by Chinese-speaking threat actors including #EarthLusca ! More than 50 C2s have been found to communicate with this #malware family !

https://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.html

#cyberespionage #china

Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion

Trend Micro

Trend Micro reports on a new China-nexus cyberespionage group (dubbed Earth Krahang) that primarily targets Southeast Asia and then Europe, America, and Africa. It has multiple connections to another Chinese APT Earth Lusca (aka Aquatic Panda, Bronze University, Charcoal Typhoon, RedHotel) and potential links to i-SOON. Trend Micro was able to retrieve multiple files from Earth Krahang’s servers, including samples, configuration files, and log files from its attack tools. MITRE ATT&CK TTPs and IOC provided. 🔗 https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html

#EarthKrahang #cyberespionage #EarthLusca #AquaticPanda #CharcoalTyphoon #RedHotel #China #APT #IOC #threatintel #MITREATTACK

Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks

Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.

Trend Micro
Very proud to release my latest research which exposes a Chinese-speaking threat actor to attacks on Taiwan before the national elections - https://www.trendmicro.com/en_us/research/24/b/earth-lusca-uses-geopolitical-lure-to-target-taiwan.html #APT #cyberespionage #isoon #i-soon #EarthLusca
Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections

During our monitoring of Earth Lusca, we noticed a new campaign that used Chinese-Taiwanese relations as a social engineering lure to infect selected targets.

Trend Micro