Earth Wendigo targets government and education in Hong Kong and Taiwan, known for email exfiltration via JavaScript backdoors.
Analyst brief
Earth Wendigo targets government and education sectors primarily in Hong Kong and Taiwan. Key TTPs include exfiltrating emails by injecting JavaScript backdoors into a widely used webmail system and sending spear-phishing emails with malicious links to political activists. Defenders should focus on detecting suspicious JavaScript injections in webmail platforms and enhancing user awareness against spear-phishing campaigns.
Earth Wendigo
unknown
Earth Wendigo is a threat actor from China that has been targeting several organizations — including government organizations, research institutions, and universities in Taiwan — since May 2019, aiming to exfiltrate emails from targeted organizations via the injection of JavaScript backdoors to a webmail system that is widely used in Taiwan. The threat actor also sent spear-phishing emails embedded with malicious links to multiple individuals, including politicians and activists, who support movements in Tibet, the Uyghur region, or Hong Kong.
Which regions and sectors does the Earth Wendigo threat actor target?+
Earth Wendigo primarily targets government organizations, research institutions, and universities in Hong Kong and Taiwan, as well as political activists who support movements in Tibet, the Uyghur region, or Hong Kong.
What is the primary technical method used by Earth Wendigo to exfiltrate emails?+
The primary method is exfiltrating emails by injecting JavaScript backdoors into a webmail system that is widely used in Taiwan.