Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » China-linked Earth Arax uses vargeit and Cobecon in multi-stage cyber intrusions
Celebrities

China-linked Earth Arax uses vargeit and Cobecon in multi-stage cyber intrusions

By April 1, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Multi-stage cyber intrusion

Cybersecurity researchers are shedding light on a new China-related threat actor called Earth Alux, which targets a variety of key sectors including government, technology, logistics, manufacturing, telecommunications, IT services, retail, and more in the Asia-Pacific (APAC) and Latin America (LATAM) regions.

“The first sighting of that activity was in the second quarter of 2023. At the time, it was mainly observed in the APAC region,” Trend Micro researchers Renato Vermajo, Tedley and Teochen said in a technical report released Monday. “It was discovered in Latin America around mid-2024.”

The main targets of hostile collective span countries such as Thailand, the Philippines, Malaysia, Taiwan and Brazil.

The infection chain starts with the exploitation of vulnerable services in web applications exposed to the internet and then uses them to drop Godzilla web shells to facilitate the deployment of additional payloads, including backdoors, known as Vargeit or Cobecon (also known as Cobalt Strike Beacon).

Cybersecurity

Vargeit provides the ability to directly load tools from a Command and Control (C&C) server into newly generated processes in Microsoft Paint (“mspaint.exe”), facilitating reconnaissance, collection, and extraction.

“Vargeit is also the primary way Earth Alux operates supplementary tools for a variety of tasks, such as lateral movement and network discovery,” the researchers said.

A worth mentioning point here is that Vargeit is used as the first, second or later backdoor, while Cobeacon is adopted as the first phase backdoor. The latter is released via a loader called Masqloader, or via a rust-based command-line shellcode loader, Rsbinject.

It has also been observed that subsequent iterations of MASQLoader overwrite NTDLL.DLL hooks inserted by security programs to detect suspicious processes running on Windows, allowing malware and payloads embedded within it to fly under the radar.

Running Vargeit unfolds more tools, such as Railload, a loader component codename that is run using a technique known as DLL sideload and is used to run encrypted payloads in another folder.

The second payload is a persistence and time sit module called Railsetter that creates a scheduled task that launches Railload, as well as modifying the timestamps associated with the Railload artifacts on the compromised host.

Vargeit and controller interaction

“MasQloader is also used by other groups other than Earth Alux,” Trend Micro said. “In addition, the difference in the code structure of MasQloader compared to other tools such as Railsetter and Railload suggests that Masqloader development is separate from those toolsets.”

The most distinctive aspect of Vargeit is its ability to support 10 different channels for C&C communication via HTTP, TCP, UDP, ICMP, DNS, and Microsoft Outlook. The final aspect leverages commands that exchange graph APIs in a pre-determined format using attacker-controlled mailbox draft folders.

Cybersecurity

Specifically, messages from the C&C server are prepared with R_, but backdoor messages are marked with P_. Among its wide range of features is extensive data collection and command execution, making it a powerful malware in the arsenal of threat actors.

“Earth Alux has done some testing on Railload and Railsetter,” Trend Micro said. “These include detection tests and attempts to find new hosts for DLL sideloads. DLL sideload tests include Zeroeye, a popular open source tool within the Chinese-speaking community.

Hacking groups have also been found to utilize Virtest, another testing tool widely used by the Chinese-speaking community, to ensure that the tool is in sufficient condition to maintain long-term access to the target environment.

“Earth Alux represents the threat of sophisticated and evolving cyberspion, leveraging a diverse range of toolkits and advanced technologies to penetrate and compromise across different sectors, particularly in the APAC region and Latin America,” the researchers concluded. “The continuous testing of the group and the development of its tools further demonstrates its commitment to improving its capabilities and avoiding detection.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGlobal retailer overshares CSRF tokens on Facebook
Next Article Approximately 24,000 IPS targets in coordination login scan campaigns PAN-OS GlobalProtect

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

Trending Posts

Bonnie Tyler has recovered from coma but remains ‘very unwell’ after emergency surgery

June 16, 2026

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.