Home/Threat Actor/Earth Krahang
Threat Actor

Earth Krahang

earth_krahang · china · active since 2022-early

Earth Krahang (canonical Trend Micro naming per March 18, 2024 disclosure by Joseph C Chen and Daniel Lunghi) is a People's Republic of China state-aligned cyber-espionage cluster active publicly since early 2022 with primary operational mission objectives of intelligence collection from government entities worldwide, strong focus on Southeast Asia with secondary targeting in Europe, America, and Africa.

approximately 70 confirmed victims across 23 countries with at least 48 government entities compromised (including 11 government ministries in one country); operationally distinct from the 32 China-attributed clusters already curated in the corpus through (1) signature inter- government trust-abuse operational tradecraft, using compromised government infrastructure to attack other government entities including documented 796-address spearphishing campaign from compromised government mailbox within a single agency delivering RAR + LNK + Xdealer payloads, (2) aggressive public-facing server vulnerability scanning operational tradecraft using sqlmap + nuclei + xray + vscan + pocsuite + wordpressscan toolchain with recursive .git/.idea folder searches and directory brute- forcing, (3) custom RESHELL + XDealer backdoors as signature malware.

notable exploited vulnerabilities include CVE-2023-32315 (OpenFire RCE) and CVE-2022-21587 (Oracle E-Business Suite RCE)

operational connections include multiple connections with Earth Lusca (curated separately) tracked as separate intrusion set due to independent infrastructure and unique backdoors, potential links to Chinese company I-Soon (subject of February 2024 leak revealing Chinese-government cyber-espionage contractor role), and Palo Alto Networks Unit 42 moderate- confidence GALLIUM RESHELL operational overlap.

fills the inter-government trust-abuse government-targeting China- aligned APT cell in the curated corpus.

china confidence: high 10 aliases

Profile

Earth Krahang (canonical Trend Micro naming Earth Krahang) is a People's Republic of China state-aligned cyber- espionage cluster active publicly since early 2022, with primary operational mission objectives of intelligence collection from government entities worldwide, strong focus on Southeast Asia with secondary targeting in Europe, America, and Africa. Per Trend Micro researchers Joseph C Chen and Daniel Lunghi's March 18, 2024 canonical disclosure, the cluster has accumulated "approximately 70 confirmed victims across 23 countries" with at least 48 government entities confirmed compromised, including "in one country, the group successfully compromised organizations across 11 different government ministries." The cluster is operationally significant and distinct from the broader 32 China-attributed clusters already curated in this corpus through three signature operational-pattern features: (1) Inter-government trust-abuse operational tradecraft. The cluster's signature and operationally most-distinctive tradecraft: using compromised government infrastructure to attack other government entities.

Per Trend Micro: "abusing the infrastructure to host malicious payloads, proxy attack traffic, and sending spear-phishing emails to government- related targets using compromised government email accounts." The inter-government trust-abuse pattern operationally exploits trust relationships between government entities, compromised government email accounts and domains provide more credible spear-phishing pretexts than typical attacker-controlled infrastructure. Operationally documented incident: 796-address spearphishing campaign from a compromised government mailbox within a single agency, delivering RAR archives containing LNK files that installed Xdealer malware with decoy documents about the targeted agency. (2) Aggressive public-facing server vulnerability scanning operational tradecraft.

Earth Krahang scans public-facing servers aggressively using recursive searches for folders like .git and .idea, directory brute-forcing, and subdomain enumeration to discover unmaintained or misconfigured assets. Toolchain includes sqlmap, nuclei, xray, vscan, pocsuite, and wordpressscan, operationally consistent with broader Chinese-APT-cluster offensive-tooling standardization. Notable exploited vulnerabilities include CVE-2023-32315 (OpenFire RCE), CVE-2022-21587 (Oracle E-Business Suite RCE), and similar.

(3) Custom RESHELL + XDealer backdoors as signature malware. Cluster-defining custom backdoors operationally distinguish Earth Krahang from competing China-nexus clusters. Operational phases: (1) OPERATIONAL EMERGENCE (Early 2022).

Trend Micro began monitoring the APT campaign in early 2022. (2) INTER-GOVERNMENT TRUST ABUSE OPERATIONAL ERA (2022- Present). Signature operational tradecraft established and operationally refined.

(3) TREND MICRO CANONICAL DISCLOSURE (March 18, 2024). "Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks", operationally established canonical cluster naming and documented the full operational tradecraft pattern. (4) CONTINUED OPERATIONS (2024-2026). Sustained operational tempo.

Picus Security January 2026 analysis documents continued cluster activity.

Operational connections noted in the curated corpus
  • Earth Lusca operational connection: Trend Micro identified multiple connections with Earth Lusca (curated separately as earth_lusca.yaml), but tracks Earth Krahang as a separate intrusion set based on independent infrastructure and unique backdoors.
  • Potential I-Soon connection: Trend Micro flagged potential operational links to Chinese company I-Soon, operationally placing Earth Krahang within the broader Chinese-government-cyber-contractor ecosystem identified in the February 2024 I-Soon leak documentation.
  • GALLIUM partial overlap (RESHELL malware family): Palo Alto Networks Unit 42 attributes (with moderate confidence) a particular cluster using RESHELL malware to GALLIUM (curated separately as gallium.yaml), operationally suggesting RESHELL has broader distribution across multiple China-nexus clusters.
Signature operational tradecraft
  • Inter-government trust-abuse spearphishing: compromised government mailboxes deliver malicious RAR + LNK + Xdealer/RESHELL payloads to internal government targets with agency-themed decoy documents.
  • Aggressive vulnerability scanning toolchain: sqlmap, nuclei, xray, vscan, pocsuite, wordpressscan + recursive .git/.idea folder searches + directory brute-forcing + subdomain enumeration.
  • Public-facing application exploitation: CVE-2023-32315 (OpenFire), CVE-2022-21587 (Oracle E-Business Suite), adjacent RCE vulnerabilities.
  • Custom RESHELL + XDealer backdoors: cluster-defining custom malware families. Xdealer has both Linux and Windows variants.
  • Government-server-as-staging tradecraft: using compromised government web servers to scan vulnerabilities in other government targets, host malicious payloads, and proxy attack traffic.
  • Southeast Asia primary geographic focus: distinct from competing China-aligned cluster geographic priorities; complemented by secondary Europe / America / Africa operations. The cluster fills the inter-government trust-abuse government- targeting China-aligned APT cell in this curated corpus, complementing the broader China-attributed cluster coverage (now 33 clusters total). Earth Krahang is operationally distinct from the 32 adjacent China-attributed clusters through signature inter-government trust-abuse tradecraft, aggressive vulnerability scanning operational pattern, custom RESHELL + XDealer backdoors, primary Southeast Asia geographic focus, and potential I-Soon Chinese-contractor ecosystem connection.

Aliases

10
earth krahangearth-krahangearth_krahangtrend micro earth krahangearth_lusca_overlap_clusteri_soon_contractor_linki-soon adjacentgallium_reshell_overlapearth_krahang_chinaearth krahang apt

Notable Campaigns

9
2024-2026Continued Operations Through 2024-2026
2024Trend Micro Canonical Earth Krahang Disclosure (March 18, 2024)
2024Potential Links to I-Soon Chinese Cyber-Espionage Contractor (February 2024 Disclosure Era)
2024GALLIUM Partial Overlap (Palo Alto Networks Unit 42 Moderate-Confidence Attribution)
2022-PresentInter-Government Trust Abuse, Signature Operational Tradecraft (Active Since 2022)
2022-PresentAggressive Public-Facing Server Vulnerability Scanning (Active Since 2022)
2022-PresentOperational Connection With Earth Lusca (China-Nexus)
2022-2024Spearphishing 796 Addresses From Compromised Government Mailbox (Signature Incident)
2022Earth Krahang Operational Emergence (Early 2022)

Attribution & Reporting

Attributed by
Trend MicroPalo Alto Networks Unit 42MandiantCrowdStrikeMicrosoft Threat Intelligence CenterRecorded Future Insikt GroupPicus SecurityESETSOPHOS X-OpsSymantec / Broadcom Threat Hunter TeamSentinelOne / SentinelLabsVolexity
Key reporting
reportTrend Micro (Joseph C Chen, Daniel Lunghi): Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks (March 18, 2024), canonical comprehensive Earth Krahang disclosure
reportPalo Alto Networks Unit 42: GALLIUM + RESHELL Malware Family Moderate-Confidence Attribution
reportPicus Security: Earth Krahang APT Group, Global Government Cyberespionage Campaigns 2022-2024 and TTP Analysis (January 2026)
reportMandiant: China-Nexus Cluster Tracking, Earth Krahang Adjacent Activity
reportCrowdStrike Global Threat Report: China State-Aligned Cluster Tracking
reportMicrosoft Threat Intelligence: China-Aligned Cluster Tracking
reportRecorded Future Insikt Group: China State-Aligned Cyber-Espionage Tracking
reportESET: Earth Krahang Adjacent Cluster Tracking
reportSOPHOS X-Ops: China-Nexus APT Cluster Tracking
reportSymantec / Broadcom Threat Hunter Team: China-Aligned APT Continued Tracking
reportSentinelLabs: China-Nexus Cluster Operational Analysis
reportVolexity: Earth Krahang Operational Profile
reportI-Soon February 2024 Leak Documentation (broader Chinese cyber-contractor ecosystem context)
reportMITRE ATT&CK Group G1040, Earth Krahang
reportMalpedia Actor Profile: Earth Krahang

Operational

State sponsor

People's Republic of China state-aligned cyber-espionage cluster. Trend Micro canonical naming Earth Krahang per March 18, 2024 disclosure by researchers Joseph C Chen and Daniel Lunghi. The cluster operates within the broader China-nexus APT ecosystem with multiple operational connections to Earth Lusca (Trend Micro canonical naming for a China-aligned cluster curated separately as earth_lusca.yaml in this corpus), Trend Micro identified "multiple connections with a China-nexus threat actor we track as Earth Lusca" but assesses Earth Krahang as a "separate intrusion set" because "the campaign employs independent infrastructure and unique backdoors." Trend Micro also documented potential links to a Chinese contractor company named I-Soon. The I-Soon link is operationally significant, I-Soon was the subject of a February 2024 leak that revealed the company's role as a Chinese- government cyber-espionage contractor providing offensive cyber services to Chinese state security entities including the Ministry of State Security (MSS) and Ministry of Public Security (MPS). Palo Alto Networks Unit 42 separately "published a report that attributes, with moderate confidence, a particular cluster using RESHELL malware to GALLIUM" (curated separately as gallium.yaml in this corpus) , operationally suggesting that the RESHELL malware family (one of Earth Krahang's signature custom backdoors) may have operational overlap with GALLIUM as well. The cluster is operationally distinct from the 32 China-attributed clusters already curated in this corpus through (a) signature government-to-government trust-abuse operational tradecraft , using compromised government infrastructure to attack other government entities.

(b) signature scale of government- sector compromise (~70 confirmed victims across 23 countries, 48+ government entities confirmed compromised including 11 different government ministries in one country)

(c) custom RESHELL + XDealer (Xdealer) backdoors.

(d) public-facing server vulnerability scanning as signature primary initial- access vector (with sqlmap, nuclei, xray, vscan, pocsuite, wordpressscan toolchain)

(e) primary geographic focus on Southeast Asia (operationally distinct from competing China-aligned cluster geographic priorities)

(f) potential operational connection to I-Soon Chinese-government cyber-espionage contractor. No formal attribution to a specific Chinese government agency or contractor relationship has been definitively asserted publicly, Trend Micro tracks the cluster at the broader "China-nexus" level with potential I-Soon connection.

Motivations
cyber_espionage_intelligence_collection, government_intelligence_collection, inter_government_trust_abuse_for_lateral_compromise, government_infrastructure_exploitation, government_email_account_takeover, chinese_state_aligned_strategic_intelligence_collection, southeast_asia_regional_intelligence_collection
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)59/60 · 98%
Analytics (MITRE CAR)30/60 · 50%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)14/60 · 23%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

2 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SUBDOMAIN ENUMERATION TOOLING
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin