China-Supported Earth Baku Broadens Cyber Assaults Across Europe, the Middle East, and Africa

The threat actor known as Earth Baku, backed by China, has expanded its scope of operations beyond the Indo-Pacific region since late 2022, targeting Europe, the Middle East, and Africa.

Recent targets include Italy, Germany, the UAE, and Qatar, with additional incidents observed in Georgia and Romania. The group has focused on sectors such as government, media, telecommunications, technology, healthcare, and education.

According to Trend Micro researchers Ted Lee and Theo Chen, the group has refined its methods, utilizing public-facing applications like IIS servers as initial access points. Once inside, they deploy advanced malware to compromise the victim’s systems. This information was highlighted in a recent analysis.

This development follows similar findings from Zscaler and Mandiant, which also reported on the group’s use of malware families including DodgeBox (also known as DUSTPAN) and MoonWalk (also known as DUSTTRAP). Trend Micro has identified these as StealthReacher and SneakCross.

Affiliated with APT41, Earth Baku has been using the StealthVector tool since October 2020. Their attack methods typically involve exploiting public-facing applications to deploy the Godzilla web shell, which facilitates further payload delivery.

StealthReacher is an upgraded variant of the StealthVector backdoor loader and is used to activate SneakCross—a modular implant that appears to be a successor to ScrambleCross, using Google services for command-and-control communication.

The group’s post-exploitation tactics also involve tools like iox and Rakshasa, along with the Tailscale VPN for persistence. Data exfiltration is managed through MEGAcmd, a command-line utility that transfers data to MEGA cloud storage.

“The group has incorporated new loaders such as StealthVector and StealthReacher to discreetly deploy backdoor components and has introduced SneakCross as their latest modular backdoor,” the researchers explained.

“Earth Baku also employs various post-exploitation tools including a tailored iox tool, Rakshasa, Tailscale for persistence, and MEGAcmd for efficient data exfiltration.”

More Articles & Posts