Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

10+ Prime Day vacuum cleaner deals carefully selected by professional vacuum testers

Beyoncé reveals how Blue Ivy influenced Jay-Z’s hair journey in new clip

Olivia Rodrigo explains why jealousy is often featured in her songs

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » Earth Car Targets Southeast Asia with rootkits and cloud-based data theft tools
Celebrities

Earth Car Targets Southeast Asia with rootkits and cloud-based data theft tools

By April 28, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rootkit and cloud-based data t

The government and telecommunications sector in Southeast Asia have been targeting a “sophisticated” campaign since June 2024 by a new Advanced Persistent Threat (APT) group called Earth Kurma.

Attacks are using micro-trends to utilize custom malware, rootkits and cloud storage services for data removal. The Philippines, Vietnam, Thailand and Malaysia are one of the prominent targets.

“This campaign poses high business risks through targeted spying, qualification theft, persistent scaffolding established through kernel-level rootkits, and data removal via trusted cloud platforms,” ​​security researchers Nick Dye and Sunny Lou said in an analysis published last week.

The activities of threat actors date back to November 2020, with intrusions relying primarily on services such as Dropbox and Microsoft Onedrive using tools such as TESDAT and SimpoboxSpy.

Two other notable malware families in the Armory include Rootkits such as Krnrat and Moriya. The latter has been previously observed in attacks targeting well-known organizations in Asia and Africa as part of a Tunnelsnake called the espionage campaign.

Cybersecurity

Trend Micro also said that the SimpoboxSpy and exfiltration scripts used in the attack overlap with another APT group called Toddycat. However, the decisive attribution remains decisive.

Currently, it is not currently known how threat actors gain initial access to their target environment. The initial scaffolding is then abused and scans and performs lateral movement using a variety of tools such as NBTSCAN, LADON, FRPC, WMIHACKER, ICMPINGER, and more. What is being deployed is a keylogger called Kmlog to harvest the credentials.

It is worth noting that the use of the open source radon framework was attributed to a China-related hacking group previously known as TA428 (aka Visicic Panda).

Host persistence is achieved by three different loader strains called Dunloader, Tesdat, and DMLoader, which can load and run the payload of the next stage into memory. These consist of cobalt strike beacons, rootkits like Krnrat and Moriya, and data removal malware.

What distinguishes these attacks is the use of the lood-the-land-the-land (lotl) technique to install legitimate system tools and features, in this case, rootkits that use Syssetup.dll, rather than introducing malware that can be easily detected by hackers.

While Moriya is designed to inspect incoming TCP packets in malicious payloads and inject shellcode into the newly generated “svChost.exe” process, KRNRAT is a fusion of five different open source projects with the capabilities of process operations, potential execution of files, execution of shellcode, command and control.

Krnrat, like Moriya, is designed to load rootkit into the user mode agent and inject it into “svchost.exe”. The user mode agent acts as a backdoor to retrieve subsequent payloads from the C2 server.

Cybersecurity

“Before removing the files, some commands executed by the loader TESDAT collected specific document files in .pdf, .doc, .docx, .docx, .xls, .xlsx, and .pptx for .pdf, .doc, .docx, .xlsx, .pptx, and .pptx. “The documents are first placed in a newly created folder named ‘TMP’. This is archived using Winrar with a specific password. ”

One of the bespoke tools used to exfoliate data is simpoboxSpy, which allows you to upload RAR archives to dropboxes with specific access tokens. According to a report by Kasperksy in October 2023, generic dropbox uploaders are “probably not used exclusively by ToddyCat.”

Another program used for the same purpose, Odriz uploads the collected information to OneDrive by specifying the OneDrive Refresh token as an input parameter.

“Earth cars are very active and continue to target countries around Southeast Asia,” Trend Micro said. “They have the ability to adapt to their victim environment and maintain a stealth presence.”

“They can also customize their toolset by reusing the same codebase from previously identified campaigns, and sometimes they can leverage the victim’s infrastructure to achieve their goals.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFirst quarter recruitment trends and forecasts for this year
Next Article Effective natural methane reduction solutions for livestock agriculture

Related Posts

Zendaya styles her ‘damp bixie’ in Berlin

June 22, 2026

Hailey Bieber debuts Skims campaign with Everyday Cotton

June 22, 2026

Reese Witherspoon sports Chanel on ‘Elle’ promotional tour

June 22, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

10+ Prime Day vacuum cleaner deals carefully selected by professional vacuum testers

Beyoncé reveals how Blue Ivy influenced Jay-Z’s hair journey in new clip

Olivia Rodrigo explains why jealousy is often featured in her songs

Zendaya styles her ‘damp bixie’ in Berlin

Trending Posts

Beyoncé reveals how Blue Ivy influenced Jay-Z’s hair journey in new clip

June 22, 2026

Olivia Rodrigo explains why jealousy is often featured in her songs

June 22, 2026

Zendaya styles her ‘damp bixie’ in Berlin

June 22, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.