Earth Alux
Earth Alux (canonical Trend Micro naming per March 31, 2025 disclosure by Lenart Bermejo + Ted Lee + Theo Chen) is a China-linked APT first observed Q2 2023 in APAC region with mid-2024 Latin America expansion, characterized by sophisticated multi- stage backdoor toolchain centered on VARGEIT primary backdoor with 10 C2 channels + COBEACON Cobalt Strike Beacon first-stage.
China-linked attribution via Trend Micro canonical assessment ("a new Chinese-speaking threat actor called Earth Alux that has targeted various key sectors such as government, technology, logistics, manufacturing, telecommunications, IT services, and retail in the Asia-Pacific (APAC) and Latin American (LATAM) regions") + Kaspersky ICS CERT Q1 2025 industrial- organization tracking + The Hacker News + Industrial Cyber industry coverage.
honest attribution complexity acknowledged: Trend Micro April 2026 Shadow-Earth-053 research notes "two other intrusion sets using VARGEIT: Earth Alux and REF7707, where the malware is called FinalDraft" with attribution overlap diagram showing connections between Earth Alux + REF7707 + SHADOW-EARTH-054 + CL-STA-0049 distinct intrusion sets sharing VARGEIT toolset, China APT cluster identity granularity remains evolving.
standalone cluster paralleling velvet_ant + storm_2603 + billbug in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.
operational target profile APAC primary geographic Q2 2023 onward with Thailand + Philippines + Malaysia + Taiwan targets + Latin America mid-2024 onward expansion with notable incidents in Brazil + multi-sector government + technology + logistics + manufacturing + telecommunications + IT services + retail + Kaspersky ICS CERT Q1 2025 industrial-organization targeting.
operational attack architecture: (1) cluster-defining GODZILLA web shell initial access via "vulnerable services in exposed servers" per Trend Micro implanting GODZILLA web shell for first-stage backdoor delivery.
(2) cluster-defining VARGEIT primary backdoor with 10 C2 channels ("The most distinctive aspect of VARGEIT is its ability to support 10 different channels for C&C communications over HTTP, TCP, UDP, ICMP, DNS, and Microsoft Outlook, the last of which leverages the Graph API to exchange commands in a predetermined format using the drafts folder of an attacker-managed mailbox. Specifically, the message from the C&C server is prepended with r_, while those from the backdoor are prefixed with p_") with signature Microsoft Outlook Graph API drafts folder covert channel tradecraft.
(3) cluster-defining COBEACON (Cobalt Strike Beacon variant) first-stage backdoor loaded via MASQLOADER or RSBINJECT; (4) cluster-defining MASQLOADER DLL side-loaded COBEACON loader with anti-API-hooking NTDLL.dll hook overwrite tradecraft ("Subsequent iterations of MASQLOADER have also been observed implementing an anti-API hooking technique that overwrites any NTDLL.dll hooks inserted by security programs to detect suspicious processes running on Windows, thereby allowing the malware and the embedded payload within it to fly under the radar") demonstrating sophisticated EDR-evasion.
(5) signature RSBINJECT Rust-based command-line shellcode loader for COBEACON ("Rust-based command-line shellcode loader... has other features that help test the shellcode using optional flags and subcommands. While RSBINJECT has been observed in attacks, its functionality suggests that it also doubles as a testing tool for shellcodes") with dual-purpose attack-tool/ testing-tool design.
(6) signature VARGEIT dual loading method with first-stage via cdb.exe debugger script + later-stages via DLL sideloading; (7) cluster-defining RAILLOAD + RAILSETTER timestomping toolchain with RAILLOAD as DLL- side-loaded encrypted-payload downloader + RAILSETTER timestamp modification on RAILLOAD artifacts plus scheduled task creation for RAILLOAD execution; (8) cluster-defining mspaint.exe (Microsoft Paint) process abuse for fileless supplemental tool loading + lateral movement + network discovery + reconnaissance + collection + exfiltration ("ability to load tools directly from its command- and-control (C&C) server to a spawned process of mspaint. As such, several mspaint processes can be observed performing tasks for the backdoor"); (9) signature MASQLOADER substitution cipher decryption with 1-3 character string hex value mapping table tradecraft.
(10) signature regular toolset testing for stealth and longevity per Trend Micro ("conduct regular tests for some of its toolsets to ensure stealth and longevity in the target environment")
cluster fills the Q2-2023-onward + VARGEIT-primary-backdoor-10-C2- channels + COBEACON-first-stage + MASQLOADER-anti- API-hooking-NTDLL-overwrite + RSBINJECT-Rust- shellcode-loader + RAILLOAD-RAILSETTER-timestomping + mspaint.exe-process-abuse + GODZILLA-web-shell- initial-access + APAC-LATAM-expansion + Chinese- speaking-threat-actor + multi-sector-targeting position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell; canonical illustration of 2023-2025 Chinese-speaking APAC+LATAM APT + VARGEIT 10-channel-C2-backdoor + Microsoft Outlook Graph API drafts folder C2 covert channel + MASQLOADER anti-API-hooking NTDLL overwrite + RSBINJECT Rust shellcode loader + RAILLOAD/RAILSETTER timestomping + mspaint.exe fileless tool loading + GODZILLA web shell initial access + Trend Micro Shadow-Earth attribution- overlap-with-VARGEIT-shared-toolset cited in essentially all subsequent Chinese APT industry analyses through 2023-2026 period.