Earth Baxia

Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Last IoC activity
2026-07-21 08:37:29
Profile updated
2026-07-07 12:17:41

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:tw country_code:cn

Context

Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing emails and exploiting the GeoServer vulnerability CVE-2024-36401 for remote code execution, deploying customized Cobalt Strike components with altered signatures, leveraging GrimResource and AppDomainManager injection techniques to deliver additional payloads, and utilizing a new backdoor named EAGLEDOOR for multi-protocol communication and payload delivery.

Exploited vulnerabilities

  • CVE-2024-36401 (vulnerability)

Reports & references

  • tgsoft.it — News Archivio (report)
  • jp.security.ntt — Appdomainmanager Injection (report)
  • Trend Micro — Earth Baxia Spear Phishing And Geoserver Exploit (report)
  • Trend Micro — Iocs%20 %20Earth%20Baxia%20Uses%20Spear Phishing%20And%20Geoserver%20Exploit%20To%20Target%20Apac.Txt (report)

External references