Earth Estries
- First seen
- 2020-01-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Last IoC activity
- 2026-06-26 08:37:22
- Profile updated
- 2026-07-07 12:05:24
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:cn country_code:tw
Context
Trend Micro found that Earth Estries relies heavily on DLL sideloading to load various tools within its arsenal. Aside from the backdoors previously mentioned, this intrusion set also utilizes commonly used remote control tools like Cobalt Strike, PlugX, or Meterpreter stagers interchangeably in various attack stages. These tools come as encrypted payloads loaded by custom loader DLLs.
Related threat objects
- GhostEmperor (threat-actor)
Reports & references
- Trend Micro — Earth Estries Targets Government Tech For Cyberespionage (report)
- sentinelone.com — Cyber Soft Power Chinas Continental Takeover (report)
Attributed from
- Earth Estries 2023-2024 Espionage Intrusions (campaign)
- Earth Estries Government & Technology Cyberespionage Campaign (campaign)