Trend Micro and TrendAI reported that China-aligned espionage groups collaborated by passing live access to already-compromised networks between intrusion sets, a model Trend calls "Premier Pass-as-a-Service." In one cited case, Earth Estries breached a Southeast Asian government environment, deployed CrowDoor and related tooling, and then enabled follow-on activity tied to Earth Naga—also tracked as Flax Typhoon, RedJuliett, or Ethereal Panda—including ShadowPad infrastructure. The reporting says this approach differs from traditional initial access brokerage because downstream operators appear to receive direct access to victim assets rather than just stolen credentials or footholds.
The activity aligns with separate reporting that RedJuliett intensified cyber espionage against Taiwanese organizations through exploitation of internet-facing network perimeter devices, while Trend Micro described Earth Estries as conducting long-term intrusions across government, telecommunications, and information service providers in APAC, Taiwan, and NATO countries. Researchers said the cooperative model can place multiple China-linked actors in the same intrusion chain or even the same process flow, complicating attribution and incident response, and they highlighted exploitation of Citrix devices including CVE-2025-5777 among the techniques used to gain or extend access.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
Trend Research reported that Earth Estries and Earth Naga were collaborating through an access-sharing model it called 'Premier Pass' or 'Premier Pass-as-a-Service.' The report assessed that Earth Estries acted as an access broker in some campaigns and that this cooperation complicates attribution.
On March 27, 2025, Trend observed a ShadowPad sample deployed from a CrowDoor network session on an infected machine in the Southeast Asian government environment. The associated CrowDoor command-and-control domain resolved to 103.175.16.77.
Since March 18, 2025, Earth Estries deployed ShadowPad through multiple vectors inside the compromised government environment, including via a Cobalt Strike SMB beacon, compromised user credentials over SMB, and CrowDoor. Trend linked the ShadowPad command-and-control server used in this activity to known Earth Naga infrastructure.
In March 2025, Trend found multiple Earth Estries-related toolsets on several internal machines in the compromised Southeast Asian government environment. The malware observed in the intrusion included Draculoader, Cobalt Strike, CrowDoor, and ShadowPad.
On January 22, 2025, Earth Estries likely used an unmanaged host to compromise a vulnerable internal web server in a Southeast Asian government environment. The group then deployed the CrowDoor backdoor on the compromised server.
Trend identified a November 2024 case in which Earth Estries appeared to provide Earth Naga with access to a major mobile retail company in the Asia-Pacific region. The case was cited as evidence of collaborative operations between the two China-aligned groups.
Trend telemetry showed Earth Estries attempted to provide Earth Naga with access to a compromised environment as early as late 2023. Trend said Earth Naga tooling was detected and blocked, and no known Earth Naga command-and-control traffic was observed in that attempt.
Trend said Earth Naga, also known as Flax Typhoon, RedJuliett, and Ethereal Panda, has targeted government agencies, telecommunications firms, military-related manufacturers, technology companies, media outlets, and academic institutions since at least 2021, with a heavy focus on Taiwan.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
trendaisecurity.com
Open sourcerecordedfuture.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.