Earth Longzhi

Aliases: SnakeCharmer

First seen
2019-02-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:05:04

Targeted industries: government-and-public-sector technology-and-telecommunications financial-services healthcare-and-pharmaceutical

Targeted regions: country_code:tw country_code:th country_code:ph country_code:fj

Context

Earth Longzhi is a subgroup of APT41 targeting organizations based in Taiwan, Thailand, the Philippines, and Fiji, and using “stack rumbling” via Image File Execution Options (IFEO), a new denial-of-service (DoS) technique to disable security software.

Reports & references

  • picussecurity.com — Cyber Threat Intelligence Report May 2023 (report)
  • Trend Micro — Attack On Security Titans Earth Longzhi Returns With New Tricks (report)
  • ics-cert.kaspersky.com — Apt Attacks On Industrial Organizations In H2 2022 (report)
  • Trend Micro — Hack The Real Box Apt41 New Subgroup Earth Longzhi (report)

External references