Earth Kitsune

First seen
2019-01-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:09:11

Targeted industries: government-and-public-sector media-and-entertainment

Context

Earth Kitsune is an advanced persistent threat actor that has been active since at least 2019. They primarily target individuals interested in North Korea and use various tactics, such as compromising websites and employing social engineering, to distribute self-developed backdoors. Earth Kitsune demonstrates technical proficiency and continuously evolves their tools, tactics, and procedures. They have been associated with malware such as WhiskerSpy and SLUB.

Reports & references

  • Trend Micro — Earth Kitsune Delivers New Whiskerspy Backdoor (report)
  • Trend Micro — Who Is The Threat Actor Behind Operation Earth Kitsune (report)
  • Trend Micro — Operation Earth Kitsune A Dance Of Two New Backdoors (report)
  • Trend Micro — Operation Earth Kitsune Tracking Slub S Current Operations (report)

External references