Home/Threat Actor/Earth Estries
Threat Actor

Earth Estries

earth_estries · china · active since 2020-01

Earth Estries (Trend Micro Research canonical disclosure, August 2023) is a China-aligned cyber espionage cluster focused on long-term espionage operations against governments, telecommunications providers, technology firms, and NGOs; signature operational tradecraft includes the Demodex Windows kernel rootkit for long-dwell persistent access and a sustained heavy targeting focus on telecommunications sector victims across Southeast Asia (Philippines, Malaysia, Indonesia, Vietnam, Thailand), the United States, Germany, and South Africa.

custom tooling lineage includes Demodex kernel rootkit, SNAPPYBEE loader, DeedRAT, GhostSpider, Zingdoor, DodgeBox, TrillClient infostealer, HemiGate, and Crowdoor, operationally distinguishing the cluster from commodity-tooling-dependent operations.

recent Trend Micro November 2024 operational update documented analytical overlap in time and victim sectors with the Microsoft- disclosed Salt Typhoon US telecommunications intrusions, raising open analytical questions about cluster relationship within the broader Chinese-aligned telecom-targeting sub- ecosystem.

operationally distinct from Volt Typhoon, Salt Typhoon, Silk Typhoon, Flax Typhoon, Storm-0558, and the APT* China-aligned clusters all curated separately.

china confidence: high 12 aliases

Profile

Earth Estries (Trend Micro Research canonical designation, August 2023 first-disclosure) is a China-aligned cyber espionage cluster assessed by Trend Micro with high confidence as operating as a Chinese state-aligned advanced persistent threat actor focused on long-term espionage operations against governments, telecommunications providers, technology firms, and non-governmental organizations. The cluster's signature operational tradecraft includes two operationally-distinctive elements: (1) DEMODEX WINDOWS KERNEL ROOTKIT FOR LONG-DWELL PERSISTENT ACCESS. The Demodex kernel rootkit is the cluster's most operationally-distinctive technical capability, a Windows kernel-mode rootkit that loads as a kernel driver via DLL side-loading and signed-driver-abuse tradecraft, providing kernel-level persistent access and stealth capability that operates below the user-mode process visibility of standard endpoint detection tools.

The kernel-mode persistence model operationally distinguishes Earth Estries from user-mode- only espionage clusters and provides operational dwell-time extension and detection-resistance capability consistent with the cluster's signature long-dwell espionage operational mission. (2) TELECOMMUNICATIONS-SECTOR TARGETING CONCENTRATION. Earth Estries has maintained an operationally-distinctive heavy targeting focus on telecommunications providers, including telecommunications carriers and ISPs in Southeast Asia (Philippines, Malaysia, Indonesia, Vietnam, Thailand), the United States, and selectively other regions.

The telecommunications-sector targeting concentration is analytically significant given the intelligence-collection value of telecommunications infrastructure for intelligence services seeking large-scale population-level intelligence collection (subscriber data, call records, network routing intelligence, communications metadata). The cluster's custom tooling lineage spans multiple operationally- significant malware families: Demodex (signature Windows kernel rootkit), SNAPPYBEE (signature loader / staging malware), DeedRAT (custom remote access trojan), GhostSpider (custom backdoor for persistent C2), Zingdoor (custom backdoor variant), DodgeBox (custom backdoor / dropper), TrillClient (custom infostealer for credentials), HemiGate (custom backdoor with C2 capability), and Crowdoor (custom downloader variant). The breadth of custom tooling lineage operationally distinguishes Earth Estries from commodity-tooling-dependent clusters and is consistent with sustained state-aligned tooling investment levels.

Recent Trend Micro reporting (November 2024) has documented Earth Estries operational activity overlapping in time and victim sectors with the Microsoft-disclosed Salt Typhoon US telecommunications intrusions, raising analytical questions about whether Earth Estries and Salt Typhoon represent operationally-distinct clusters within the same Chinese- aligned telecom-targeting sub-ecosystem or partially overlapping clusters. The analytical question remains partially open in public reporting and represents an active area of industry tracking. Earth Estries is operationally distinct from the broader Chinese-aligned cluster ecosystem curated in this corpus, Volt Typhoon (volt_typhoon.yaml), Salt Typhoon (salt_typhoon.yaml), Silk Typhoon (silk_typhoon.yaml), Flax Typhoon (flax_typhoon.yaml), Storm-0558 (storm_0558.yaml), and the APT* China-aligned clusters (APT1, APT3, APT10, APT17, APT31, APT40, APT41), though all operate within the broader Chinese state-aligned cyber-operations ecosystem with some operational tradecraft overlaps.

The cluster fills the Southeast-Asia-focused telecommunications-targeting cell in this curated Chinese-cluster coverage.

Aliases

12
earth_estriesearth estriesfamous sparrowfamoussparrowghostemperor adjacentsalt typhoon adjacentdemodex rootkit operatorssnappybee operatorsdeedrat operatorsghostspider operatorsuts-2987earthestries

Notable Campaigns

4
2024Trend Micro November 2024 Operational Update, Earth Estries Telecommunications and Telecom-Adjacent Targeting
2023Trend Micro Research Canonical Disclosure, Earth Estries Cluster (August 2023)
2020-2025Demodex Windows Kernel Rootkit, Operational Signature Tradecraft
2020-2025Telecommunications Sector Targeting Operational Signature

Attribution & Reporting

Attributed by
Trend Micro ResearchESET (FamousSparrow adjacent-cluster tracking)Kaspersky (GhostEmperor adjacent-cluster tracking)Mandiant (Google Threat Intelligence)CrowdStrikeMicrosoft Threat Intelligence (Salt Typhoon adjacent reporting)Recorded Future Insikt GroupSymantec / Broadcom Threat Hunter TeamSentinelOneCisco TalosCISA (US Cybersecurity and Infrastructure Security Agency)
Key reporting
reportTrend Micro Research: Earth Estries Targets Government and Tech for Cyberespionage (August 30, 2023), canonical first-disclosure
reportTrend Micro Research: Earth Estries Grow Tools Arsenal (November 2024), operational update
reportESET: FamousSparrow Adjacent Cluster Tracking (September 2021)
reportKaspersky: GhostEmperor Adjacent Cluster Tracking (October 2021)
reportMandiant / Google Threat Intelligence: Earth Estries / China Telecom Targeting Analysis
reportMicrosoft Threat Intelligence: Salt Typhoon Telecom Sector Disclosures (October-November 2024, analytically adjacent)
reportMalpedia Actor Profile: Earth Estries
reportMalpedia Malware Profiles: Demodex, SNAPPYBEE, DeedRAT, GhostSpider, Zingdoor

Operational

State sponsor

China-aligned cyber espionage cluster assessed by Trend Micro Research (canonical Earth Estries disclosure, August 2023) with high confidence to operate as a Chinese state- aligned advanced persistent threat actor focused on long-term espionage operations against governments, telecommunications providers, technology firms, and non- governmental organizations. Trend Micro's attribution is based on the cluster's operational tradecraft (long-dwell espionage operations with kernel-level rootkit deployment for persistent stealth access), targeting profile (Southeast Asian governments and telecommunications providers, consistent with Chinese state intelligence priorities in regional influence operations), infrastructure analysis (Chinese-aligned operational infrastructure patterns), and tooling overlap with adjacent Chinese-aligned clusters including FamousSparrow (ESET tracked) and GhostEmperor (Kaspersky tracked). The cluster has not been formally attributed by any government cybersecurity authority to a specific Chinese government agency, military unit, or intelligence service (MSS).

The cluster is operationally distinct from Volt Typhoon (volt_typhoon.yaml, critical infrastructure preposition), Salt Typhoon (salt_typhoon.yaml , US telecommunications intrusions 2024), Silk Typhoon (silk_typhoon.yaml, Exchange zero-day), Flax Typhoon (flax_typhoon.yaml, Taiwan-focused), Storm-0558 (storm_0558.yaml, Exchange token forging), GhostEmperor (ghostemperor.yaml), and the APT* China-aligned clusters (APT1, APT3, APT10, APT17, APT31, APT40, APT41) all curated separately, though all operate within the broader Chinese state-aligned cyber-operations ecosystem and share some operational tradecraft elements with Earth Estries. Recent Trend Micro reporting (November 2024) has documented Earth Estries operational activity overlapping in time and victim sectors with the Microsoft-disclosed Salt Typhoon US telecommunications intrusions, raising analytical questions about whether Earth Estries and Salt Typhoon represent operationally-distinct clusters within the same Chinese- aligned telecom-targeting sub-ecosystem or partially overlapping clusters, the analytical question remains partially open in public reporting.

Motivations
cyber_espionage, telecommunications_sector_intelligence_collection, government_intelligence_collection, long_dwell_persistent_access_operations, chinese_state_intelligence_priorities, regional_geopolitical_intelligence_southeast_asia
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)32/60 · 53%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SNAPPYBEE
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin