Earth Bluecrow is a suspected China-aligned cyber espionage threat actor associated with long-running intrusions in Asia and the Middle East. The group has been linked to operations targeting telecommunications, finance, and retail organizations, with reported victimology including entities in South Korea, Hong Kong, Myanmar, Malaysia, and Egypt. Earth Bluecrow is notably associated with use of the BPFDoor backdoor in espionage-focused campaigns and has been connected to activity against a Korean telecommunications company in 2025. The actor is known for leveraging BPFDoor, a stealth-oriented backdoor that abuses Berkeley Packet Filter functionality to conceal command-and-control activation and maintain persistence on compromised systems. This malware design supports covert long-term access, remote control, lateral movement, and collection of sensitive information from victim environments. Reporting indicates the group has used an updated BPFDoor controller since at least 2021, suggesting continued tool maintenance and operational refinement. Earth Bluecrow’s tradecraft is consistent with advanced intrusion sets focused on durable access and low-visibility operations inside enterprise networks. Observed objectives align with strategic intelligence collection rather than disruptive or purely financially motivated activity. Publicly referenced aliases in the available data include EarthBluecrow and earthbluecrow.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Earth Bluecrow is conducting long-term cyber espionage using BPFDoor backdoor, targeting communication, finance, and retail sectors in Asia and the Middle East.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.