Earth Baxia
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-07-21 08:37:29
- Profile updated
- 2026-07-07 12:17:41
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:tw country_code:cn
Context
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing emails and exploiting the GeoServer vulnerability CVE-2024-36401 for remote code execution, deploying customized Cobalt Strike components with altered signatures, leveraging GrimResource and AppDomainManager injection techniques to deliver additional payloads, and utilizing a new backdoor named EAGLEDOOR for multi-protocol communication and payload delivery.
Exploited vulnerabilities
- CVE-2024-36401 (vulnerability)
Reports & references
- tgsoft.it — News Archivio (report)
- jp.security.ntt — Appdomainmanager Injection (report)
- Trend Micro — Earth Baxia Spear Phishing And Geoserver Exploit (report)
- Trend Micro — Iocs%20 %20Earth%20Baxia%20Uses%20Spear Phishing%20And%20Geoserver%20Exploit%20To%20Target%20Apac.Txt (report)