Earth Kasha is a threat actor tracked by Trend Micro and assessed as related to the broader “APT10 umbrella,” though the content explicitly cautions that it is not necessarily identical to legacy APT10. The group has historically targeted public institutions and academics with spear-phishing emails, and reporting covering activity from early 2023 to early 2024 describes an expanded focus on targets in Japan, Taiwan, and India, including advanced technology, government, private sector, manufacturing, aviation, and hi-tech organizations. Trend Micro assessed Earth Kasha with medium confidence as the operator of the recent LODEINFO campaign. The group’s tradecraft evolved from spear-phishing toward exploitation of public-facing applications for initial access, including SSL-VPN and file-storage services. Reported exploited vulnerabilities include Array AG (CVE-2023-28461), Proself (CVE-2023-45727), and FortiOS/FortiProxy (CVE-2023-27997). Post-compromise activity described in the content includes credential theft, lateral movement, persistence, and data exfiltration. Earth Kasha used SMB together with schtasks.exe or sc.exe for lateral movement, abused RDP, and used vssadmin to copy registry hives and ntds.dit from Active Directory servers. It also used legitimate Microsoft tools including csvde.exe, nltest.exe, and quser.exe for reconnaissance and collection, and compressed stolen files before exfiltration over backdoor channels or RDP sessions. Malware and tooling directly associated with Earth Kasha in the content include LODEINFO, Cobalt Strike, MirrorStealer, NOOPDOOR, and NOOPLDR. LODEINFO is described as a backdoor used by the group since 2019, with newer versions adding commands and in-memory execution of DLLs or shellcode. MirrorStealer was used to steal credentials from browsers, email clients, Group Policy Preferences, and SQL Server Management Studio. NOOPDOOR is described as a sophisticated second-stage backdoor with active and passive communication modes, advanced encryption, anti-analysis checks, a custom DGA that changes C2 domains daily, and support for loading encrypted modules from disk. NOOPLDR is a loader for NOOPDOOR, including XML/C# and DLL variants with advanced encryption and registry-based persistence. The content also states that Earth Kasha used DLL side-loading and abuse of digital signatures associated with MS13-098/CVE-2013-3900 for payload delivery. The reporting notes overlap between Earth Kasha’s TTPs and those of other China-nexus actors, particularly Earth Tengshe (A41APT), including exploitation of SSL-VPNs and abuse of scheduled tasks and RDP. The content further notes possible shared use of vulnerabilities or access brokers among China-linked actors. Known alias information in the provided content is limited to Earth Kasha itself.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A related intrusion set under the broader 'APT10 umbrella' discussed as distinct from legacy APT10, targeting Japan, Taiwan, and India using public-facing application exploitation and spear-phishing.
Earth Kasha is a China-nexus threat actor known for cyber-espionage campaigns primarily targeting Japan, and more recently Taiwan and India, focusing on advanced technology and government sectors. They use custom malware (LODEINFO, NOOPDOOR, MirrorStealer), Cobalt Strike, and exploit public-facing application vulnerabilities for initial access. Their operations include credential theft, lateral movement, and data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.