Earth Longzhi
Aliases: SnakeCharmer
- First seen
- 2019-02-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:05:04
Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical
Targeted regions: country_code:tw country_code:th country_code:ph country_code:fj
Context
Earth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Execution Options (IFEO), a new denial-of-service (DoS) technique to disable security software.
Reports & references
- picussecurity.com — Cyber Threat Intelligence Report May 2023 (report)
- Trend Micro — Attack On Security Titans Earth Longzhi Returns With New Tricks (report)
- ics-cert.kaspersky.com — Apt Attacks On Industrial Organizations In H2 2022 (report)
- Trend Micro — Hack The Real Box Apt41 New Subgroup Earth Longzhi (report)