Earth Wendigo

First seen
2019-05-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:02:30

Targeted industries: education-and-nonprofits government-and-public-sector

Targeted regions: country_code:tw

Context

Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and universities in Taiwan — since May 2019, aiming to exfiltrate emails from targeted organizations via the injection of JavaScript backdoors to a webmail system that is widely used in Taiwan. The threat actor also sent spear-phishing emails embedded with malicious links to multiple individuals, including politicians and activists, who support movements in Tibet, the Uyghur region, or Hong Kong.

Reports & references

  • Trend Micro — Earth Wendigo Injects Javascript Backdoor To Service Worker For (report)

External references