Earth Krahang is a Chinese-nexus cyberespionage intrusion set active since at least early 2022. It primarily targets government entities, particularly foreign-affairs-related organizations, with a strong operational focus on Southeast Asia and additional activity affecting organizations in Europe, the Americas, and Africa. Telecommunications providers, postal organizations, media firms, and financial institutions have also been targeted. Reporting has identified approximately 70 confirmed victims in 23 countries and 116 targeted entities across 35 countries. Earth Krahang obtains access through spear-phishing and exploitation of internet-facing servers, including Oracle Web Applications Desktop Integrator and Openfire vulnerabilities. It abuses compromised government web and email infrastructure to host payloads, proxy attack traffic, conduct reconnaissance, and distribute phishing messages to other government targets. The actor has deployed RESHELL, XDealer/DinodasRAT (including its Linux Linodas variant), Cobalt Strike, PlugX, and ShadowPad, and uses SoftEther VPN to retain access to compromised networks. Post-compromise activity includes credential dumping, password spraying against webmail services, theft and use of authenticated web-session cookies, mailbox collection and exfiltration, network and vulnerability scanning, remote execution, lateral movement, and privilege escalation on Windows and Linux. Earth Krahang uses scheduled tasks, services, remote desktop enablement, web shells, DLL side-loading, masquerading, tunneling, and modified or replaced system utilities to establish persistence, evade detection, and conceal artifacts. The PONDSNAKE campaign has been assessed with medium-to-high confidence as attributable to Earth Krahang. The group has notable operational and tooling overlaps with Earth Lusca/RedHotel and has been linked in reporting to the Chinese contractor I-Soon.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
58 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
9 malware families attributed to this actor across reporting.
4 additional families tracked in Mallory.
5 CVEs this actor has used in observed campaigns. 5 of them exploited in the wild.
Earth Krahang was seen ... enabling remote desktop connections, credential dumping, network scanning, WMIC execution and privilege escalation on both Windows and Linux systems (CVE-2021-4034, CVE-2021-22555, and CVE-2016-5195).
Earth Krahang was seen ... enabling remote desktop connections, credential dumping, network scanning, WMIC execution and privilege escalation on both Windows and Linux systems (CVE-2021-4034, CVE-2021-22555, and CVE-2016-5195).
Earth Krahang was seen ... enabling remote desktop connections, credential dumping, network scanning, WMIC execution and privilege escalation on both Windows and Linux systems (CVE-2021-4034, CVE-2021-22555, and CVE-2016-5195).
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as Oracle Web Applications Desktop Integrator CVE-2022-21587 (CVSS 9.8) ... to install backdoors such as Cobalt Strike, RESHELL, and XDealer.
Earth Krahang is known to conduct spear-phishing attacks and exploiting vulnerable public-facing servers such as ... OpenFire CVE-2023-32315 (CVSS 7.5) to install backdoors such as Cobalt Strike, RESHELL, and XDealer.
126 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Espionage activity cluster reportedly linked to i-Soon; attributed (medium-to-high confidence) to the PONDSNAKE campaign targeting government and financial institutions, using exploitation/spear-phishing for initial access and deploying multiple C2 and remote admin tools.
Uses attack-oriented proxies such as SoftEther for persistent access and covert operations.
Chinese-nexus cyber espionage activity targeting organizations in Southeast Asia, Africa, and South America, using the cross-platform DinodasRAT/Linodas backdoor to maintain footholds on Linux servers and support persistence, reverse shells, file operations, user monitoring, and evasion via a filter module that hides artifacts from system tools.
Chinese espionage-focused threat actor with a strong Southeast Asia focus, targeting a wide range of entities globally via spear-phishing and exploitation of public-facing servers to deploy multiple malware families and steal sensitive data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.