Earth Gelert is a tracked threat cluster associated with exploitation of a Windows shortcut user-interface misrepresentation technique involving crafted .lnk files that conceal malicious command-line arguments from users. It has been identified among a broader set of state-sponsored intrusion groups observed using this technique in campaigns dating back to at least 2017. The activity is consistent with espionage-oriented operations and information theft rather than disruptive or ransomware-driven tradecraft. Operations linked to this cluster use malicious shortcut files to disguise execution behavior from victims by abusing how Windows displays shortcut properties. This enables hidden command execution while presenting the shortcut as benign, often with deceptive naming and iconography to increase the likelihood of user interaction. The broader campaigns associated with this technique have targeted organizations in government, finance, telecommunications, military and defense, energy, and think tanks or NGOs across multiple regions worldwide. Earth Gelert appears in reporting alongside other named intrusion sets from North Korea, Iran, Russia, and China that have used the same .lnk-based concealment method, indicating shared or parallel adoption of the technique across state-sponsored ecosystems. High-confidence public details specific to Earth Gelert’s malware families, sub-groups, or country attribution are not currently available from the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Earth Gelert is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.