Hacking

Earth Baxia APT Exploits GeoServer Flaw in Attacks on APAC Government Agencies

Published  ·  3 min read

A suspected advanced persistent threat (APT) group from China, identified as Earth Baxia, has been linked to cyber attacks targeting government organizations in Taiwan and other Asia-Pacific (APAC) countries. The group exploited a critical vulnerability in OSGeo GeoServer GeoTools (CVE-2024-36401, CVSS score: 9.8) in a sophisticated campaign that has raised alarms across the region.

The activity, discovered in July 2024 by Trend Micro, involves a multi-stage attack that uses both spear-phishing emails and the GeoServer vulnerability to deploy malicious tools, including Cobalt Strike and a previously undocumented backdoor named EAGLEDOOR. The campaign has specifically targeted government agencies, telecommunication companies, and the energy sector in countries like Taiwan, South Korea, Vietnam, Thailand, and the Philippines.

The Infection Chain

The Earth Baxia APT operation follows a multi-pronged infection chain, starting with spear-phishing emails containing decoy documents and exploiting the GeoServer flaw. Once the victim interacts with the phishing email or the exploit, Cobalt Strike is deployed as a command-and-control (C2) tool, while EAGLEDOOR serves as the information-gathering malware that allows further payload delivery.

The researchers noted the use of GrimResource and AppDomainManager injection techniques to deploy additional malware, lowering the victim's defenses. A ZIP archive attachment containing a decoy MSC file named RIPCOY is used to download the next-stage malware.

EAGLEDOOR and Cobalt Strike

The backdoor EAGLEDOOR is a central element of the attack. It offers the threat actors capabilities to communicate with the C2 server using DNS, HTTP, TCP, and even Telegram protocols. The Telegram Bot API is utilized for exfiltrating data, uploading and downloading files, and executing additional payloads. The harvested data is typically exfiltrated via curl.exe.

The similarity in tactics between Earth Baxia and another APT41-linked cluster identified by NTT Security Holdings suggests potential overlap in these campaigns. Both operations have targeted the Philippine military, Vietnamese energy organizations, and Taiwanese government sectors. Additionally, they have shared command-and-control domains mimicking legitimate services like Amazon Web Services and Microsoft Azure.

Advanced Techniques and Persistent Threats

Earth Baxia’s use of GeoServer exploits, Cobalt Strike, and the custom EAGLEDOOR backdoor highlights the complexity and adaptability of their operations. The group not only mimicked public cloud service domains to avoid detection but also employed multi-protocol support in their malware, making it harder to mitigate their attacks.

The researchers warned that such campaigns pose a significant threat to the targeted countries, with the government, energy, and telecommunication sectors being high-value targets for espionage and disruption

Professional Services

Explore Our Cybersecurity Services

Our insights are backed by hands-on service delivery. If your business needs professional cybersecurity support, our UK-based specialists are ready to help.

© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067