Cyber Security News

Earth Alux Hackers Employ VARGIET Malware to Attack Organizations

The cybersecurity landscape has been disrupted by Earth Alux, a China-linked advanced persistent threat (APT) group actively conducting espionage operations since the second quarter of 2023.

Initially targeting the Asia-Pacific region, the group expanded its operations to Latin America by mid-2024, primarily focusing on government, technology, logistics, manufacturing, telecommunications, IT services, and retail sectors in countries including Thailand, the Philippines, Malaysia, Taiwan, and Brazil.

Earth Alux primarily gains initial access by exploiting vulnerable services in exposed servers, subsequently implanting web shells such as GODZILLA to facilitate the delivery of their malware.

Overview of Earth Alux (Source – Trend Micro)

The group primarily utilizes VARGEIT as its primary backdoor, alongside COBEACON, with VARGEIT employed across multiple stages of their attacks to maintain persistence and execute malicious operations.

Trend Micro researchers identified that the attackers employ sophisticated techniques to ensure stealth and longevity in target environments, regularly testing their toolsets before deployment.

Once established in a network, Earth Alux focuses on long-term data collection and exfiltration, potentially leading to disrupted operations and significant financial losses across critical industries.

VARGEIT operates as a multi-channel configurable backdoor with remarkable capabilities, including drive information collection, process monitoring, file manipulation, command line execution, and the ability to inject additional tools without leaving traces on the filesystem.

VARGEIT and controller interaction (Source – Trend Micro)

What makes this malware particularly concerning is its ability to leverage multiple communication channels, with the Outlook channel (using Graph API) being predominantly used in observed attacks.

The mspaint Injection Technique

The most distinctive aspect of VARGEIT’s operation is its unique mspaint injection technique.

Rather than dropping files onto the target system, the malware opens instances of mspaint.exe into which it injects shellcode received directly from command-and-control servers.

This technique allows Earth Alux to execute additional tools without leaving detectable artifacts on disk.

Launch process (Source – Trend Micro)

The injection process utilizes RtlCreateUserThread, VirtualAllocEx, and WriteProcessMemory APIs, as shown in this example command pattern observed during reconnaissance activities:-

C:\Windows\System32\mspaint.exe sElf98RqkF ldap   

These mspaint processes perform various malicious activities, including security event log examination, group policy discovery, network/LDAP reconnaissance, and data exfiltration.

During exfiltration operations, the malware connects to attacker-controlled cloud storage buckets, sending compressed archives of collected sensitive information.

The increasing sophistication of Earth Alux’s tactics highlights the evolving nature of cyber espionage threats facing organizations today, particularly those in strategic sectors across Asia-Pacific and Latin America regions.

Are You from SOC/DFIR Team? - Try Free Malware Research with ANY.RUN - Start Now

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

China-linked APT24 Hackers New BadAudio Compromised Legitimate Public Websites to Attack Users

APT24, a sophisticated cyber espionage group linked to China's People's Republic, has launched a relentless…

58 minutes ago

Broadcom Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack

The Cl0p ransomware group has claimed responsibility for infiltrating Broadcom's internal systems as part of…

2 hours ago

Critical Grafana Vulnerability Let Attackers Escalate Privilege

Grafana Labs has disclosed a critical security vulnerability affecting Grafana Enterprise that could allow attackers…

2 hours ago

Critical ASUSTOR Vulnerability Let Attackers Execute Malicious Code with Elevated Privileges

A critical security vulnerability has been discovered in ASUSTOR backup and synchronization software, allowing attackers…

3 hours ago

Windows 11 to Hide BSOD Crash Errors on Public Displays

Microsoft has introduced a practical new feature in Windows 11 designed specifically for public-facing monitors…

4 hours ago

SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That…

6 hours ago