A suspected advanced persistent threat (APT) group from China, identified as Earth Baxia, has been linked to cyber attacks targeting government organizations in Taiwan and other Asia-Pacific (APAC) countries. The group exploited a critical vulnerability in OSGeo GeoServer GeoTools (CVE-2024-36401, CVSS score: 9.8) in a sophisticated campaign that has raised alarms across the region.
The activity, discovered in July 2024 by Trend Micro, involves a multi-stage attack that uses both spear-phishing emails and the GeoServer vulnerability to deploy malicious tools, including Cobalt Strike and a previously undocumented backdoor named EAGLEDOOR. The campaign has specifically targeted government agencies, telecommunication companies, and the energy sector in countries like Taiwan, South Korea, Vietnam, Thailand, and the Philippines.
The Infection Chain
The Earth Baxia APT operation follows a multi-pronged infection chain, starting with spear-phishing emails containing decoy documents and exploiting the GeoServer flaw. Once the victim interacts with the phishing email or the exploit, Cobalt Strike is deployed as a command-and-control (C2) tool, while EAGLEDOOR serves as the information-gathering malware that allows further payload delivery.
The researchers noted the use of GrimResource and AppDomainManager injection techniques to deploy additional malware, lowering the victim's defenses. A ZIP archive attachment containing a decoy MSC file named RIPCOY is used to download the next-stage malware.
EAGLEDOOR and Cobalt Strike
The backdoor EAGLEDOOR is a central element of the attack. It offers the threat actors capabilities to communicate with the C2 server using DNS, HTTP, TCP, and even Telegram protocols. The Telegram Bot API is utilized for exfiltrating data, uploading and downloading files, and executing additional payloads. The harvested data is typically exfiltrated via curl.exe.
The similarity in tactics between Earth Baxia and another APT41-linked cluster identified by NTT Security Holdings suggests potential overlap in these campaigns. Both operations have targeted the Philippine military, Vietnamese energy organizations, and Taiwanese government sectors. Additionally, they have shared command-and-control domains mimicking legitimate services like Amazon Web Services and Microsoft Azure.
Advanced Techniques and Persistent Threats
Earth Baxia’s use of GeoServer exploits, Cobalt Strike, and the custom EAGLEDOOR backdoor highlights the complexity and adaptability of their operations. The group not only mimicked public cloud service domains to avoid detection but also employed multi-protocol support in their malware, making it harder to mitigate their attacks.
The researchers warned that such campaigns pose a significant threat to the targeted countries, with the government, energy, and telecommunication sectors being high-value targets for espionage and disruption