Earth Alux

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:21:11

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:cn country_code:jp country_code:kr country_code:ph country_code:id country_code:th country_code:sg country_code:cl country_code:br

Context

Earth Alux is a China-linked APT group known for conducting cyberespionage attacks across various sectors, including government, technology, and telecommunications. They primarily exploit vulnerable services in exposed servers to gain initial access, implanting web shells like GODZILLA and deploying backdoors such as VARGEIT and COBEACON. The group employs tools like RSBINJECT and MASQLOADER for lateral movement and network discovery, while also utilizing RAILSETTER for persistence through mspaint injection. Their operations have predominantly targeted the APAC region and have extended to Latin America, with a focus on exfiltrating sensitive information to attacker-controlled cloud storage.

Reports & references

  • security.com — Jewelbug Crypto Fraud Espionage (report)
  • Trend Micro — The Espionage Toolkit Of Earth Alux (report)

External references