HomeSecurityEarth Estries group steals information from governments around the world

Earth Estries group steals information from governments around the world

The Earth Estries group steals information from governments and technology organizations around the world.

The campaign comes from “Earth Estries.” The previously unknown group has been around since at least 2020, according to a report from Trend Micro, and is partially an offshoot of another cyberattack group, FamousSparrow. While the targets are limited to a few industries, they span the globe from the U.S. to the Philippines, Germany, Taiwan, Malaysia, and South Africa.

The Earth Estries group has a penchant for using DLL sideloading to execute any of its three custom malware – two backdoors and an infostealer – along with other tools such as Cobalt Strike. The perpetrators behind Earth Estries work with high-level resources and operate with specialized skills and experience in cyberattacks and illicit activities,” Trend Micro researchers wrote.

See also: DarkGate malware activity increases

Earth Estries

What tools does Earth Estries use?

The Earth Estries team has three unique malware tools: Zingdoor, TrillClient, and HemiGate.

Zingdoor is an HTTP backdoor that was first deployed in June 2022, and has only been deployed in limited cases since then. It is written in Golang (Go), giving it cross-platform capabilities, and is packed with UPX. It can retrieve system and Windows service information, enumerate, upload or download files, and execute arbitrary commands on a host system.

TrillClient is a combination installer and infostealer, written in Go and packaged in a Windows cabinet file (.cab). The stealer is designed to collect browser credentials, with the added ability to execute commands or suspend at will, or at random intervals, in order to avoid detection. Along with Zingdoor, it features a custom obfuscator designed to make analysis tools difficult.

The most versatile tool in the group is the HemiGate backdoor. This multi-scenario, all-in-one malware includes functions for keylogging, screenshot taking, command execution, and monitoring, adding, deleting, and editing files, directories, and processes.

See also: New Ransomed ransomware group uses a new extortion tactic

Earth Estries group steals information from governments around the world

The methods of the Earth Estries group

In April, researchers discovered the Earth Estries group using compromised accounts with administrative privileges to infect an organization’s internal servers—how those accounts were compromised remains unknown. They deployed Cobalt Strike to establish a foothold on the system , then used server message block (SMB) and the WMI command line to bring their own malware to the party.

In its methods, Earth Estries gives the impression of a clean, deliberate operation.

For example, to execute the malware on the host machine, it chooses the rushed method of DLL sideloading. The researchers explained that the hackers “clean up” the existing backdoor upon completion of each round of operation and deploy a new piece of malware when they start another round. We believe they do this to reduce the risk of discovery and detection.

See also: VMware Aria: Vulnerable to critical SSH authentication bypass vulnerability

DLL sideloading and another tool used by the group – Fastly CDN – are popular with APT41 subgroups such as Earth Longzhi. Trend Micro also found overlaps between Earth Estries’ backdoor loader and FamousSparrow. However, the exact origins of the Earth Estries group are unclear. It also doesn’t help that its C2 infrastructure is spread across five continents, spanning all hemispheres: from Canada to Australia, Finland to Laos, with the largest concentration in the US and India.

Researchers may soon learn more about the group, as its campaign against government and technology organizations around the world continues to this day.

Source of information: darkreading.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS