Home/Threat Actor/Earth Alux
Threat Actor

Earth Alux

earth_alux · china · active since 2023-04

Earth Alux (canonical Trend Micro naming per March 31, 2025 disclosure by Lenart Bermejo + Ted Lee + Theo Chen) is a China-linked APT first observed Q2 2023 in APAC region with mid-2024 Latin America expansion, characterized by sophisticated multi- stage backdoor toolchain centered on VARGEIT primary backdoor with 10 C2 channels + COBEACON Cobalt Strike Beacon first-stage.

China-linked attribution via Trend Micro canonical assessment ("a new Chinese-speaking threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail in the Asia-Pacific (APAC) and Latin American (LATAM) regions") + Kaspersky ICS CERT Q1 2025 industrial- organization tracking + The Hacker News + Industrial Cyber industry coverage.

honest attribution complexity acknowledged: Trend Micro April 2026 Shadow-Earth-053 research notes "two other intrusion sets using VARGEIT: Earth Alux and REF7707, where the malware is called FinalDraft" with attribution overlap diagram showing connections between Earth Alux + REF7707 + SHADOW-EARTH-054 + CL-STA-0049 distinct intrusion sets sharing VARGEIT toolset, China APT cluster identity granularity remains evolving.

standalone cluster paralleling velvet_ant + storm_2603 + billbug in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

operational target profile APAC primary geographic Q2 2023 onward with Thailand + Philippines + Malaysia + Taiwan targets + Latin America mid-2024 onward expansion with notable incidents in Brazil + multi-sector government + technology + logistics + manufacturing + telecommunications + IT services + retail + Kaspersky ICS CERT Q1 2025 industrial-organization targeting.

operational attack architecture: (1) cluster-defining GODZILLA web shell initial access via "vulnerable services in exposed servers" per Trend Micro implanting GODZILLA web shell for first-stage backdoor delivery.

(2) cluster-defining VARGEIT primary backdoor with 10 C2 channels ("The most distinctive aspect of VARGEIT is its ability to support 10 different channels for C&C communications over HTTP, TCP, UDP, ICMP, DNS, and Microsoft Outlook, the last of which leverages the Graph API to exchange commands in a predetermined format using the drafts folder of an attacker-managed mailbox. Specifically, the message from the C&C server is prepended with r_, while those from the backdoor are prefixed with p_") with signature Microsoft Outlook Graph API drafts folder covert channel tradecraft.

(3) cluster-defining COBEACON (Cobalt Strike Beacon variant) first-stage backdoor loaded via MASQLOADER or RSBINJECT; (4) cluster-defining MASQLOADER DLL side-loaded COBEACON loader with anti-API-hooking NTDLL.dll hook overwrite tradecraft ("Subsequent iterations of MASQLOADER have also been observed implementing an anti-API hooking technique that overwrites any NTDLL.dll hooks inserted by security programs to detect suspicious processes running on Windows, thereby allowing the malware and the embedded payload within it to fly under the radar") demonstrating sophisticated EDR-evasion.

(5) signature RSBINJECT Rust-based command-line shellcode loader for COBEACON ("Rust-based command-line shellcode loader... has other features that help test the shellcode using optional flags and subcommands. While RSBINJECT has been observed in attacks, its functionality suggests that it also doubles as a testing tool for shellcodes") with dual-purpose attack-tool/ testing-tool design.

(6) signature VARGEIT dual loading method with first-stage via cdb.exe debugger script + later-stages via DLL sideloading; (7) cluster-defining RAILLOAD + RAILSETTER timestomping toolchain with RAILLOAD as DLL- side-loaded encrypted-payload downloader + RAILSETTER timestamp modification on RAILLOAD artifacts plus scheduled task creation for RAILLOAD execution; (8) cluster-defining mspaint.exe (Microsoft Paint) process abuse for fileless supplemental tool loading + lateral movement + network discovery + reconnaissance + collection + exfiltration ("ability to load tools directly from its command- and-control (C&C) server to a spawned process of mspaint. As such, several mspaint processes can be observed performing tasks for the backdoor"); (9) signature MASQLOADER substitution cipher decryption with 1-3 character string hex value mapping table tradecraft.

(10) signature regular toolset testing for stealth and longevity per Trend Micro ("conduct regular tests for some of its toolsets to ensure stealth and longevity in the target environment")

cluster fills the Q2-2023-onward + VARGEIT-primary-backdoor-10-C2- channels + COBEACON-first-stage + MASQLOADER-anti- API-hooking-NTDLL-overwrite + RSBINJECT-Rust- shellcode-loader + RAILLOAD-RAILSETTER-timestomping + mspaint.exe-process-abuse + GODZILLA-web-shell- initial-access + APAC-LATAM-expansion + Chinese- speaking-threat-actor + multi-sector-targeting position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell; canonical illustration of 2023-2025 Chinese-speaking APAC+LATAM APT + VARGEIT 10-channel-C2-backdoor + Microsoft Outlook Graph API drafts folder C2 covert channel + MASQLOADER anti-API-hooking NTDLL overwrite + RSBINJECT Rust shellcode loader + RAILLOAD/RAILSETTER timestomping + mspaint.exe fileless tool loading + GODZILLA web shell initial access + Trend Micro Shadow-Earth attribution- overlap-with-VARGEIT-shared-toolset cited in essentially all subsequent Chinese APT industry analyses through 2023-2026 period.

china confidence: high 15 aliases
Sigma rules200 YARA rules0 Live IOCs0 CVEs exploited0

Profile

Earth Alux (canonical Trend Micro naming per March 31, 2025 disclosure) is a China-linked APT first observed Q2 2023 in APAC region with mid-2024 Latin America expansion, characterized by sophisticated multi-stage backdoor toolchain (VARGEIT primary backdoor with 10 C2 channels + COBEACON Cobalt Strike Beacon first-stage + MASQLOADER + RSBINJECT loaders + RAILLOAD + RAILSETTER timestomping toolchain). China-linked attribution via Trend Micro canonical assessment ("Chinese-speaking threat actor") + Kaspersky ICS CERT Q1 2025 industrial-organization tracking. Honest attribution complexity: VARGEIT shared toolset spans Earth Alux + REF7707 (FinalDraft) + SHADOW-EARTH-054 + CL-STA-0049 per Trend Micro April 2026 Shadow-Earth research.

Standalone cluster paralleling velvet_ant + storm_2603 + billbug in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Operational target profile
  • APAC primary geographic Q2 2023 onward, Thailand + Philippines + Malaysia + Taiwan.
  • Latin America mid-2024 onward, notably Brazil.
  • Government primary sector.
  • Technology + logistics + manufacturing + telecom + IT services + retail secondary sectors.
  • Industrial organizations Q1 2025 Operational attack architecture: (1) GODZILLA web shell initial access (cluster- defining): vulnerable services in internet- exposed web applications (2) VARGEIT primary backdoor 10 C2 channels (cluster-defining): HTTP + TCP + UDP + ICMP + DNS + Microsoft Outlook Graph API drafts folder (r_/p_ prefix protocol) (3) COBEACON Cobalt Strike Beacon first-stage (cluster-defining): loaded via MASQLOADER or RSBINJECT (4) MASQLOADER anti-API-hooking NTDLL overwrite (cluster-defining): substitution-cipher decryption + EDR-evasion via NTDLL.dll hook overwriting (5) RSBINJECT Rust-based shellcode loader (signature): dual-purpose attack-tool/testing- tool (6) VARGEIT dual loading (signature): cdb.exe debugger script first-stage + DLL sideloading later-stage (7) RAILLOAD + RAILSETTER timestomping toolchain (cluster-defining): timestamp modification + scheduled task for RAILLOAD execution (8) mspaint.exe process abuse (cluster-defining): fileless tool execution for reconnaissance + collection + exfiltration (9) Regular toolset testing (signature): stealth + longevity in target environment per Trend Micro The cluster fills the Q2-2023-onward + VARGEIT- primary-backdoor-10-C2-channels + COBEACON-first- stage + MASQLOADER-anti-API-hooking + RSBINJECT- Rust + RAILLOAD-RAILSETTER-timestomping + mspaint. exe-process-abuse + GODZILLA-web-shell + APAC- LATAM-expansion + Chinese-speaking-threat-actor position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Aliases

15
earth_aluxearth aluxearth_alux_aptearth alux china-linked aptearth alux trend micro march 2025 disclosureearth alux vargeit primary backdoor 10 c2 channelsearth alux cobeacon cobalt strike beacon first stageearth alux masqloader rust rsbinject shellcode loadersearth alux railload railsetter timestomping toolchainearth alux mspaint.exe process abuse for tool loadingearth alux godzilla web shell initial accessearth alux microsoft outlook graph api drafts folder c2 channelearth alux apac latin america government technology logisticsearth alux thailand philippines malaysia taiwan brazil targetsearth alux kaspersky ics cert q1 2025 industrial organization targeting

Notable Campaigns

12
2026Earth Alux Trend Micro Shadow-Earth April 2026 Attribution Overlap Acknowledgment
2025Earth Alux Kaspersky ICS CERT Q1 2025 Industrial Organization Targeting
2024Earth Alux Latin America Expansion (Mid-2024)
2023-2026Continued Industry Reference Status (2023-2026)
2023-2025Earth Alux GODZILLA Web Shell Initial Access Signature
2023-2025Earth Alux VARGEIT Primary Backdoor 10 C2 Channels Signature
2023-2025Earth Alux VARGEIT mspaint.exe Process Abuse Signature
2023-2025Earth Alux VARGEIT Dual Loading Method Signature
2023-2025Earth Alux MASQLOADER Anti-API-Hooking NTDLL Overwrite Signature
2023-2025Earth Alux RSBINJECT Rust-Based Shellcode Loader Signature
2023-2025Earth Alux RAILLOAD + RAILSETTER Timestomping Toolchain Signature
2023Earth Alux Origin, APAC Q2 2023 First Observation

Attribution & Reporting

Attributed by
Trend Micro (canonical March 31, 2025 The Espionage Toolkit of Earth Alux disclosure by Lenart Bermejo + Ted Lee + Theo Chen)The Hacker News (canonical April 1, 2025 China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions coverage)Industrial Cyber (canonical April 3, 2025 Trend Micro exposes Earth Alux Chinese APT analysis)Kaspersky ICS CERT (canonical Q1 2025 APT and financial attacks on industrial organizations tracking)Trend Micro (April 2026 Shadow-Earth-053 research with attribution overlap acknowledgment, REF7707 FinalDraft + SHADOW-EARTH-054 + CL-STA-0049 + Earth Alux VARGEIT shared tool ecosystem)
Key reporting
reportTrend Micro: The Espionage Toolkit of Earth Alux, A Closer Look at its Advanced Techniques (March 31, 2025), canonical first disclosure by Lenart Bermejo + Ted Lee + Theo Chen
reportThe Hacker News: China-Linked Earth Alux Uses VARGEIT and COBEACON in Multi-Stage Cyber Intrusions (April 1, 2025)
reportIndustrial Cyber: Trend Micro exposes Earth Alux Chinese APT targeting critical infrastructure in APAC, Latin America (April 3, 2025)
reportKaspersky ICS CERT: APT and financial attacks on industrial organizations in Q1 2025 (June 19, 2025)
reportTrend Micro: Inside Shadow-Earth-053, A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia (April 2026), canonical VARGEIT shared-toolset attribution overlap acknowledgment

Operational

State sponsor

China state-sponsored or Chinese-speaking-threat- actor per Trend Micro canonical March 31, 2025 attribution + Kaspersky ICS CERT Q1 2025 analysis ("Trend Micro researchers uncovered a new Chinese- speaking threat actor called Earth Alux"). Honest attribution note: while Trend Micro identifies Earth Alux as "China-linked," the specific China cluster identity within broader Chinese APT ecosystem remains uncertain, Trend Micro's Shadow-Earth research April 2026 acknowledges attribution overlap and "TTPs from the related reports" not matching between SHADOW-EARTH-053/054 vs Earth Alux despite shared VARGEIT tool usage. Attribution chain: (1) Trend Micro canonical March 31, 2025 disclosure: per Trend Micro: "Trend Research's consistent monitoring and investigation efforts have uncovered Earth Alux's stealthy activities and advanced techniques. One of the tools in the arsenal of this advanced persistent threat group (APT) is its primary backdoor, VARGEIT... The attacks are targeted toward the Asia-Pacific (APAC) and Latin American regions, hitting key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail." Authors: Lenart Bermejo + Ted Lee + Theo Chen. (2) Trend Micro Q2 2023 first observation + mid-2024 LATAM expansion: per Trend Micro: "The first sighting of its activity was in the second quarter of 2023.

back then, it was predominantly observed in the APAC region. Around the middle of 2024, it was also spotted in Latin America." (3) The Hacker News canonical April 2025 coverage: per The Hacker News: "Cybersecurity researchers have shed light on a new China-linked threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail in the Asia-Pacific (APAC) and Latin American (LATAM) regions." (4) Industrial Cyber + Kaspersky ICS CERT Q1 2025 industrial-organization tracking: per Kaspersky ICS CERT: "Trend Micro researchers uncovered a new Chinese-speaking threat actor called Earth Alux targeting various key sectors, including government, technology, logistics, manufacturing, telecom, IT, and retail in the Asia-Pacific region and Latin America. First observed in Asia in Q2 2023, Earth Alux has also been active in Latin America since mid-2024." (5) Trend Micro April 2026 Shadow-Earth-053/054 research attribution-overlap acknowledgment: per Trend Micro: "We know of two other intrusion sets using VARGEIT: Earth Alux and REF7707, where the malware is called FinalDraft. Again, none of the TTPs from the related reports match the activity we observed from SHADOW-EARTH-054. Figure 3. Attribution overlap diagram showing connections between SHADOW-EARTH-054, CL-STA-0049, Earth Alux, and REF7707." Honest attribution complexity acknowledged: VARGEIT tool usage spans Earth Alux + REF7707 (FinalDraft) + SHADOW-EARTH-054 + CL-STA-0049 distinct intrusion sets, likely shared-toolset across overlapping but distinct Chinese APT clusters. Operational mission objective: Cyberespionage with long-term data collection + exfiltration objective per Trend Micro ("Left undetected, the attack can maintain a foothold in the system and carry out cyberespionage. The long- term collection and exfiltration of data could lead to far-reaching consequences"). Multi-sector government + technology + critical infrastructure targeting.

Operational target profile
  • APAC region primary geographic Q2 2023 onward, Thailand + Philippines + Malaysia + Taiwan.
  • Latin America secondary geographic mid-2024 onward, notably Brazil.
  • Government primary sector.
  • Technology + logistics + manufacturing + telecommunications + IT services + retail secondary sectors.
  • Industrial organizations Q1 2025 per Kaspersky ICS CERT The cluster fills the Q2-2023-onward + VARGEIT- primary-backdoor-10-C2-channels + COBEACON-first- stage + MASQLOADER-anti-API-hooking-NTDLL-hook- overwrite + RSBINJECT-Rust-shellcode-loader + RAILLOAD-RAILSETTER-timestomping-toolchain + mspaint. exe-process-abuse + GODZILLA-web-shell-initial- access + APAC-LATAM-expansion + Chinese-speaking- threat-actor + multi-sector-targeting position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.
Motivations
china_state_sponsored_or_chinese_speaking_apt_cyberespionage, apac_latam_multi_sector_long_term_data_collection_exfiltration, vargeit_primary_backdoor_10_c2_channels_signature_capability, microsoft_outlook_graph_api_drafts_folder_c2_channel_signature_capability, mspaint_exe_process_abuse_fileless_tool_loading_signature_tradecraft, masqloader_anti_api_hooking_ntdll_overwrite_signature_tradecraft, railload_railsetter_timestomping_scheduled_task_toolchain_signature, godzilla_web_shell_initial_access_signature_tradecraft
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)56/60 · 93%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

0 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MASQLOADERMASQLOADER ANTI-API-HOOKING NTDLL.DLL HOOK OVERWRITE TRADECRAFTMASQLOADER SUBSTITUTION CIPHER 1-3 CHARACTER STRING HEX VALUE TABLEMSPAINT.EXE MICROSOFT PAINT PROCESS ABUSE TOOL LOADING RECONNAISSANCE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin