A sophisticated cyber espionage campaign by a newly identified advanced persistent threat (APT) group called Earth Kurma has been targeting government and telecommunications sectors across Southeast Asia since June 2024, according to Trend Micro researchers.
The campaign primarily affects the Philippines, Vietnam, Thailand, and Malaysia, utilizing custom malware, kernel-level rootkits, and legitimate cloud storage services for data exfiltration. Security researchers Nick Dai and Sunny Lu warn that this operation poses significant business risks through targeted espionage, credential theft, and persistent access via sophisticated rootkits.
## Attack Timeline and Tools
Earth Kurma’s activities date back to November 2020. The group leverages Dropbox and Microsoft OneDrive to exfiltrate sensitive data using specialized tools like TESDAT and SIMPOBOXSPY. Their arsenal also includes advanced rootkits such as KRNRAT and Moriya, with the latter previously observed in the TunnelSnake campaign targeting organizations across Asia and Africa.
While some tools share similarities with another APT group called ToddyCat, definitive attribution remains inconclusive.
## Attack Methodology
After gaining initial access through currently unknown methods, Earth Kurma conducts network scanning and lateral movement using tools including NBTSCAN, Ladon, FRPC, WMIHACKER, and ICMPinger. The group deploys a keylogger called KMLOG to harvest credentials.
Persistence is maintained through three loader variants:
– DUNLOADER
– TESDAT
– DMLOADER
These loaders execute next-stage payloads including Cobalt Strike Beacons, rootkits, and data exfiltration malware.
## Advanced Evasion Techniques
Earth Kurma employs living-off-the-land techniques, using legitimate system components like syssetup.dll to install rootkits rather than introducing easily detectable malware. Their KRNRAT rootkit combines five open-source projects to enable process manipulation, file hiding, shellcode execution, and covert C2 communication.
Before exfiltration, the attackers collect documents with extensions including .pdf, .doc, .docx, .xls, .xlsx, .ppt, and .pptx, placing them in a “tmp” folder and archiving them with WinRAR using specific passwords.
Trend Micro concludes that Earth Kurma remains highly active across Southeast Asia, demonstrating adaptability to victim environments while maintaining stealth. The group effectively reuses code from previous campaigns to customize their toolsets, sometimes leveraging victims’ own infrastructure to achieve their objectives.
