🔴 [LATEST] 313 TEAM TARGETS AL RAJHI BANK AND SAUDI CIVIL DEFENSE, SITES UNREACHABLE FROM DOZENS OF LOCATIONS    ◆    🔴 [LATEST] DDOS QATAR INVESTMENT AUTHORITY: 1 CRITICAL SOVEREIGN WEB PORTAL DOWN    ◆    🔴 [LATEST] RIPPERSEC TARGETS ISRAEL CART: 1 CRITICAL E-COMMERCE PLATFORM DISRUPTED    ◆    🔴 [LATEST] US NAVY DDOS ATTACK: 3 CRITICAL MILITARY PORTALS DISRUPTED    ◆    🔴 [LATEST] QATAR LIVING DDOS ATTACK: 1 CRITICAL EXPATRIATE PORTAL DISRUPTED

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Flag
EARTH KRAHANG

/actor/earth-krahang/  ·  0 intel reports

Year Established
2022
Attribution
China (MSS Affiliated)
Motivation
Espionage, Government Intelligence Collection
Modus Operandi (MO)
Compromised government infrastructure for lateral attacks, spear-phishing, VPN exploitation, Southeast Asia focus
Primary Aliases
Earth Krahang

Earth Krahang is a Chinese state-sponsored APT group identified by Trend Micro researchers in 2024, notable for a particularly audacious operational tactic: compromising the email and web infrastructure of government agencies and using those legitimised government accounts to conduct spear-phishing attacks against other governments , effectively weaponising one nation's government against its allies and partners.

This infrastructure abuse strategy provides Earth Krahang with significant advantages: spear-phishing emails sent from genuine government email servers are far more likely to bypass spam filters, and recipients are less likely to be suspicious of communications appearing to originate from trusted foreign government entities. This approach demonstrates sophisticated understanding of how trust hierarchies in government communications can be exploited.

Earth Krahang has targeted government ministries across Southeast Asia, South Asia, and Africa , regions of significant strategic interest to China's Belt and Road Initiative and broader geopolitical agenda. The group exploits vulnerabilities in public-facing web servers and VPN appliances for initial access, before establishing persistent access through web shells and custom backdoors.

Trend Micro's investigation linked Earth Krahang to another Chinese APT group, Earth Lusca, suggesting shared infrastructure and possible organisational connections within China's intelligence apparatus. The group's focus on government-to-government compromise chains makes them a particular concern for foreign ministries and diplomatic services globally, as a single successful intrusion can compromise the security of multiple allied government communications simultaneously.

Cyber Espionage Tactics and Persistence Mechanisms: Operational tracking indicates that Earth Krahang executes long-term cyber espionage campaigns aligned with strategic intelligence requirements. The threat group weaponizes spear-phishing lures with malicious Office attachments, exploits unpatched edge appliances and VPN gateways, and establishes covert command-and-control (C2) channels using custom backdoors and legitimate administrative binaries. Defending against these advanced persistent threats requires comprehensive endpoint detection and response (EDR) visibility, continuous credential auditing, and proactive threat hunting across sensitive network enclaves.

STATUS: ACTIVE CLASSIFICATION: STATE-SPONSORED (APT) LAST SEEN: Unknown

> LINKED_INTEL_REPORTS (0)

[NULL] No intel reports found for this actor.

> cd ../articles