Earth Tengshe is a China-linked cyber espionage threat actor associated with the A41APT campaign and assessed to have ties or operational overlap with the broader APT10 ecosystem. The group has targeted organizations in Japan and Taiwan, including Japanese companies and their overseas branch offices, and has focused on compromising internet-facing enterprise infrastructure to gain initial access. Observed intrusion vectors include exploitation of vulnerabilities in VPN appliances and Microsoft Exchange Server, as well as the use of stolen credentials. Earth Tengshe is known for post-compromise activity centered on credential access, lateral movement, persistence, and data theft. Reported tooling and malware associated with the actor include SigLoader, SodaMaster, HUI Loader, Jackpot, China Chopper, Mimikatz, PsExec, and credential-dumping utilities. The actor has used reconnaissance and administrative commands after exploitation, deployed webshells on exposed servers, and leveraged DLL side-loading and shellcode injection to load payloads into legitimate processes. Scheduled tasks and other autorun mechanisms have been used for persistence, while utilities such as WinRAR and directory-query tools have supported collection and exfiltration activity. Malware linked to Earth Tengshe has shown continued evolution. SigLoader variants have incorporated altered compile times and modified encryption and decryption routines, while SodaMaster variants have expanded command support to include credential theft, screenshot capture, keylogging control, execution of DLLs and shellcode, and process termination. In 2021 activity, the actor also exploited the ProxyShell vulnerability chain on Microsoft Exchange and deployed the Jackpot webshell on IIS-facing systems. Earth Tengshe has additionally been identified among state-sponsored groups exploiting a Windows shortcut user-interface misrepresentation flaw involving crafted .lnk files to conceal malicious command-line arguments from users. This activity aligns with espionage-oriented operations and broader information theft objectives. Public reporting has noted overlaps between Earth Tengshe, BRONZE RIVERSIDE, and APT10-related activity, but attribution based solely on shared tooling remains insufficient. The strongest supported assessment is that Earth Tengshe is a China-based espionage actor operating within a cluster of closely related Chinese intrusion activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Earth Tengshe is a China-nexus threat actor associated with the APT10 umbrella, known for targeting private sector industries (electronics, energy, automotive, defense) in Japan, Taiwan, Thailand, and the US. They use custom malware and exploit public-facing applications for initial access, with overlaps in TTPs with Earth Kasha.
Only appears in a reference title as another named actor associated with SigLoader-related reporting, not as a primary actor discussed in the presentation body.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.