Earth Balayang is a tracked threat actor associated with exploitation of a Windows shortcut (.lnk) user-interface misrepresentation vulnerability, ZDI-CAN-25373, also tracked as ZDI-25-148. The actor is one of multiple state-sponsored intrusion sets observed using crafted shortcut files that conceal malicious command-line arguments from users, enabling deceptive initial access and payload delivery while reducing the likelihood of user detection. This tradecraft relies on whitespace padding within shortcut metadata so that malicious commands are not visibly exposed in the Windows properties interface, often combined with spoofed document-like presentation to make the shortcut appear benign. Campaigns linked to actors exploiting this technique have primarily supported espionage and information theft objectives. Victim organizations associated with this broader activity span government, finance, telecommunications, military and defense, energy, and think tanks or non-governmental organizations across multiple world regions. The available information supports Earth Balayang’s use of malicious .lnk-based initial access and defense-evasion tradecraft, but does not provide high-confidence, actor-specific details on malware families, sub-groups, or uniquely attributable downstream post-compromise behaviors beyond participation in this exploitation cluster.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed by Trend as a threat actor associated with the broader ZDI-CAN-25373 exploitation activity.
Earth Balayang is an APT group exploiting ZDI-CAN-25373 for espionage and data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.