Trend Micro reported that the Earth Minotaur threat actor is conducting multi-platform attacks using the MOONSHINE Exploit Kit to gain initial access and the DarkNimbus backdoor to maintain control of compromised systems. The activity highlights an intrusion chain built to target more than one operating environment, giving the actor flexibility to compromise victims and establish persistent access across diverse enterprise infrastructure.
The campaign combines exploitation and post-compromise tooling in a way that supports sustained operations after the initial breach. By pairing the MOONSHINE Exploit Kit with the DarkNimbus backdoor, Earth Minotaur can move from exploitation to persistence and remote control, underscoring the risk posed by threat actors that maintain adaptable malware and access capabilities across multiple platforms.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing Earth Minotaur's multi-platform attacks involving the MOONSHINE exploit kit and the DarkNimbus backdoor. The reference does not provide earlier dated events, so the publication itself is the only extractable timeline event from the available content.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 67 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
6 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcetrendmicro.com
Open sourceblog.talosintelligence.com
Open sourcecloud.google.com
Open sourceabout.fb.com
Open sourcecitizenlab.ca
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.