Earth Minotaur is a China-aligned threat actor associated with surveillance-focused operations against Tibetan and Uyghur communities. The group is linked to the MOONSHINE exploit kit and the DarkNimbus backdoor, also referred to as DarkNights in some reporting. Activity associated with this cluster has been observed since at least 2019, with DarkNimbus development assessed as active since 2018 and MOONSHINE first identified in attacks against Tibetan targets in 2019. Earth Minotaur primarily uses social engineering delivered through instant messaging applications to entice victims into opening malicious links. MOONSHINE supports masqueraded links, selective exploit delivery based on victim application and browser versions, and redirection back to benign content after exploitation. The framework has targeted vulnerable Chromium-based browsers and embedded browser components in Android applications, including exploitation of multiple known browser vulnerabilities and likely support for exploitation of WeChat-related browser components. Observed lures have impersonated government announcements, public-health news, religion-related content, travel information, and media relevant to Tibetan and Uyghur audiences. Successful compromise has led to deployment of DarkNimbus, a cross-platform backdoor with Android and Windows variants. The Android variant supports extensive surveillance and collection, including device profiling, contacts, messages, call records, location data, clipboard contents, files, screenshots, photos, recordings, and theft of communications from messaging applications through abuse of Android accessibility features. The Windows variant supports host profiling, installed software enumeration, file theft, browsing-history theft, screenshots, keylogging, clipboard theft, shell execution, and browser credential theft. DarkNimbus uses encrypted command-and-control channels and supports file transfer operations. Earth Minotaur has also been linked to DKnife, a modular adversary-in-the-middle and gateway-monitoring framework deployed on routers and edge devices. DKnife enables deep packet inspection, DNS hijacking, credential harvesting from email traffic, malware delivery through hijacked binary downloads and Android application updates, reverse proxying, packet forwarding, and exfiltration from Chinese applications. Reported payload delivery through this ecosystem has included DarkNimbus and ShadowPad. The actor is assessed as Chinese in origin. Reporting also notes ecosystem overlap with other China-aligned operators, particularly TheWizards, which has used DarkNimbus but is treated as a distinct intrusion set. MOONSHINE is assessed to remain under active development and may be shared across multiple Chinese-aligned operators, but Earth Minotaur is the cluster directly associated with its use against Tibetan and Uyghur targets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
Vulnerability Targeted Version CVE-2016-1646 Chrome 39~49
Vulnerability Targeted Version CVE-2016-5198 Chrome 50
Vulnerability Targeted Version CVE-2017-5030 Chrome 51~55
Vulnerability Targeted Version CVE-2017-5070 Chrome 56~58
Vulnerability Targeted Version CVE-2018-17463 Chrome 68~69
4 more CVEs tied to this actor tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as the developer/operator associated with DarkNimbus, creating an indirect tooling connection in the attribution discussion around TheWizard and SHADOW-VOID-044.
Surveillance-focused cluster using the MOONSHINE exploit kit to deliver DarkNimbus backdoor to Android/Windows, targeting Tibetan and Uyghur communities (WeChat-focused per content).
China-nexus activity cluster associated with operating the DKnife adversary-in-the-middle/gateway-monitoring framework since at least 2019, leveraging router/edge-device implants for deep packet inspection, traffic manipulation, credential theft, DNS hijacking, and malware delivery (including backdoors).
China-nexus activity cluster linked to MOONSHINE exploit kit and the DarkNimbus backdoor; associated monitoring led to discovery of the DKnife AitM/gateway-monitoring framework.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.