Earth Baxia is a China-linked threat actor known for targeting governments via spear-phishing, GeoServer exploits, and customized Cobalt Strike.
Analyst brief
Earth Baxia is a threat actor operating out of China, targeting government organizations in Taiwan and potentially across the APAC region. It leverages spear-phishing emails and exploits the CVE-2024-36401 vulnerability in GeoServer for remote code execution (RCE). The actor deploys customized Cobalt Strike components with altered signatures, uses GrimResource and AppDomainManager injection techniques for payload delivery, and employs a multi-protocol backdoor named EAGLEDOOR. Defenders should prioritize patching GeoServer instances, monitoring for spear-phishing attempts, and detecting Cobalt Strike beaconing or EAGLEDOOR C2 traffic.
Earth Baxia
unknown
Earth Baxia is a threat actor opearting out of China, targeting government organizations in Taiwan and potentially across the APAC region, using spear-phishing emails and exploiting the GeoServer vulnerability CVE-2024-36401 for remote code execution, deploying customized Cobalt Strike components with altered signatures, leveraging GrimResource and AppDomainManager injection techniques to deliver additional payloads, and utilizing a new backdoor named EAGLEDOOR for multi-protocol communication and payload delivery.