Security researchers at Trend Micro have identified a new China-linked threat actor called Earth Alux that has been targeting critical sectors across Asia-Pacific and Latin American regions since early 2023.
## Target Sectors and Regions
Earth Alux primarily focuses on government, technology, logistics, manufacturing, telecommunications, IT services, and retail industries. Initially observed in APAC during Q2 2023, the group expanded operations to Latin America by mid-2024. Primary targets include organizations in Thailand, the Philippines, Malaysia, Taiwan, and Brazil.
## Attack Methodology
The group’s attack chain begins by exploiting vulnerabilities in internet-exposed web applications to deploy the Godzilla web shell. This facilitates the installation of advanced backdoors:
– **VARGEIT**: A versatile backdoor that loads tools directly into Microsoft Paint processes (“mspaint.exe”) for reconnaissance and data exfiltration
– **COBEACON**: A modified Cobalt Strike Beacon deployed as a first-stage backdoor
## Advanced Evasion Techniques
Earth Alux employs sophisticated evasion methods, including:
– **MASQLOADER**: A loader that implements anti-API hooking by overwriting NTDLL.dll hooks used by security software
– **RSBINJECT**: A Rust-based command-line shellcode loader
– **RAILLOAD**: A DLL side-loading component for executing encrypted payloads
– **RAILSETTER**: A persistence module that modifies timestamps and creates scheduled tasks
## Sophisticated C&C Communications
VARGEIT stands out for its ability to support 10 different command-and-control channels over various protocols:
– HTTP, TCP, UDP, ICMP, DNS
– Microsoft Outlook (using Graph API to exchange commands through email drafts)
## Testing and Development
The group conducts extensive testing using tools popular in Chinese-speaking communities:
– **ZeroEye**: For scanning executable files to identify DLL side-loading opportunities
– **VirTest**: For testing malware evasion capabilities against security products
Earth Alux represents a sophisticated and evolving cyber espionage threat, continuously refining its capabilities to maintain long-term access to compromised environments while evading detection.
