Earth Kurma is an APT group specializing in data exfiltration against government and telecommunications sectors in Southeast Asia.
Analyst brief
Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, focused primarily on data exfiltration. The group employs advanced custom malware, including KRNRAT and MORIYA rootkits, along with tools like TESDAT and SIMPOBOXSPY, and leverages cloud storage services for data exfiltration. Defenders should prioritize monitoring for adaptive TTPs and complex evasion techniques, paying close attention to anomalous cloud service traffic, signs of rootkit activity, and network irregularities.
Earth Kurma
unknown
Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advanced custom malware, including rootkits like KRNRAT and MORIYA, and utilize cloud storage services for exfiltration. Their toolsets include TESDAT and SIMPOBOXSPY, and they demonstrate adaptive TTPs and complex evasion techniques. Attribution overlaps with other APT groups, but distinct attack patterns warrant their separate designation.