Earth Baku, a cluster linked to APT41, has expanded a long-running cyberespionage campaign against government and enterprise targets from the Indo-Pacific into Europe and the Middle East and Africa, using a steadily evolving malware arsenal and multiple intrusion paths. Trend Micro reported the group has compromised organizations in sectors including airlines, automotive, infrastructure, media, publishing, IT, and hardware, with activity tied to SQL injection on public-facing applications, exploitation of Microsoft Exchange ProxyLogon CVE-2021-26855, IIS server abuse, and web shells including China Chopper and Godzilla. Earlier reporting also described possible email-delivered LNK downloader chains and continued operational activity after public law-enforcement scrutiny.
The operators have introduced StealthReacher, an upgraded loader derived from StealthVector, to deploy SneakCross, a modular backdoor assessed as the successor to ScrambleCross and earlier Crosswalk-related tooling. Across reporting, the group was observed using Cobalt Strike Beacon, ShadowPad, Natwalk, RBRAT, Errorroot, HIGHNOON, and other loaders and backdoors, while relying on stealth techniques such as ETW disabling, process and DLL hollowing, module stomping, CFG bypass, early-bird injection, and certificate bypass. Researchers also said Earth Baku hid command-and-control through CDN services, Cloudflare Workers, and Google services, and supported persistence, tunneling, and exfiltration with customized iox, Rakshasa, Tailscale, and MEGAcmd.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
In an August 2024 report, Trend Micro described Earth Baku using the StealthReacher loader to launch the SneakCross modular backdoor, alongside tools such as Godzilla webshell, customized iox, Rakshasa, Tailscale, and MEGAcmd in recent operations.
Trend Micro reported that Earth Baku significantly expanded its operations from the Indo-Pacific into Europe and the Middle East and Africa since late 2022.
The VB2021 presentation stated that the Natwalk backdoor, which was dropped by Chatloader, was first observed in the wild in March 2021.
Trend Micro documented Earth Baku using SQL injection against public-facing web applications and exploiting Microsoft Exchange ProxyLogon vulnerability CVE-2021-26855 to gain access and deploy malware, including a China Chopper web shell on Exchange servers.
The VB2021 presentation said APT41 used the Funnyswitch loader and employed early bird code injection in 2021, reflecting continued evolution in its loader tradecraft.
The VB2021 presentation reported that Errorroot, a listening-port backdoor first found in 2019, had a new version seen in 2021 with capabilities including shell access, file transfer, victim profiling, and Mimikatz ts_session functionality.
A VB2021 presentation analyzed APT41 operations over roughly September 2020 through August 2021, describing evolving tooling, multiple initial access vectors, and targeting across sectors including government, healthcare, airlines, telecom, energy, and manufacturing.
Trend Micro said the Earth Baku cyberespionage campaign had been active since at least July 2020, targeting enterprises and government entities across the Indo-Pacific, including victims in India, Indonesia, Malaysia, the Philippines, Taiwan, and Vietnam.
Trend Micro linked the newer Earth Baku activity to an earlier cyberespionage campaign that had been ongoing since November 2018. The linkage was based on shared tooling and code similarities, including use of install.bat and the DLL name Storesyncsvc.dll.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
trendmicro.com
Open sourcetrendmicro.com
Open sourcedocuments.trendmicro.com
Open sourcevblocalhost.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.