Earth Longzhi

Description

A subgroup of APT 41.

(Trend Micro) In early 2022, we investigated an incident that compromised a company in Taiwan. The malware used in the incident was a simple but custom Cobalt Strike loader. After further investigation, however, we found incidents targeting multiple regions using a similar Cobalt Strike loader. While analyzing code similarities and tactics, techniques, and procedures (TTPs), we discovered that the actor behind this attack has been active since 2020. After clustering each intrusion, we concluded that the threat actor is a new subgroup of advanced persistent threat (APT) group APT41 that we call Earth Longzhi.

Names

NameName-Giver
Earth LongzhiTrend Micro

Country

Motivation

  • Information theft and espionage

First Seen

2020

Observed Sectors

Observed Countries

Tools

Operations

Information

Other Information

Uuid

4362a46c-19a1-444e-9755-a46be517f039

Last Card Change

2023-10-12