No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

China-Linked Actor Taps Linux Backdoor in Forceful Espionage Campaign

September 19, 2023
in Protection
0
informa



“Earth Lusca,” a China-linked cyber espionage actor that’s been actively targeting government organizations in Asia, Latin America, and other regions since at least 2021 has begun using a Linux backdoor with features that appear inspired from multiple previously known malware tools.

The malware that researchers at Trend Micro discovered and are tracking as “SprySOCKS,” is firstly a Linux variant of “Trochilus,” a Windows remote access Trojan (RAT) whose code got leaked and became publicly available in 2017.

Linux Variant of Windows Backdoor

Trochilus has multiple functions, which include allowing threat actors to remotely install and uninstall files, log keystrokes, and do screen captures, file management, and registry editing. One core feature of the malware is its ability to enable lateral movement. According to Trend Micro, SprySOCKS’ main execution routine and strings show that it originated from Trochilus and had several of its functions reimplemented for Linux systems.

In addition, the Earth Lusca implementation of SprySOCKS’ interactive shell suggests it was inspired by the Linux version of Derusbi, a continuously evolving family of RATs that advanced persistent threat actors have been using since 2008. Also, SprySOCKS’ command-and-control (C2) infrastructure resembles one that threat actors associated with a second-stage RAT called RedLeaves have used in cyber espionage campaigns for more than five years, Trend Micro said.

Like other malware of its ilk, SprySOCKS incorporates multiple functions including collecting system information, initiating an interactive shell, listing network connections, and uploading and exfiltrating files.

Elusive Threat Actor

Earth Lusca is a somewhat elusive threat actor that Trend Micro has observed since mid-2021, targeting organizations in southeast Asia and more recently in central Asia, the Balkans, Latin America, and Africa. Evidence suggests that the group is part of Winnti, a loose cluster of cyber espionage groups believed to be working on behalf of, or in support of, Chinese economic objectives.

Earth Lusca’s targets have included government and educational institutions, pro-democracy and human rights groups, religious groups, media organizations, and organizations conducting COVID-19 research. It has been especially interested in government agencies involved in foreign affairs, telecommunications, and technology. At the same time, while most of Earth Lusca’s attacks appear to be cyber espionage related, on occasion the adversary has gone after cryptocurrency and gambling firms as well, suggesting it’s also financially motivated, Trend Micro said.

In many of its attacks, the threat actor has used spear-phishing, common social engineering scams, and watering-hole attacks to try and get a foothold on a target network. Since the beginning of this year, Earth Lusca actors have also been aggressively targeting so-called “n-day” vulnerabilities in Web-facing applications to infiltrate victim networks. An n-day vulnerability is a flaw that a vendor has already disclosed but for which no patch is currently available. “Recently, the threat actor has been highly aggressive in targeting the public-facing servers of its victims by exploiting known vulnerabilities,” Trend Micro said.

Among the many such flaws that Earth Lusca has been observed exploiting this year are CVE-2022-40684, an authentication bypass vulnerability in Fortinet’s FortiOS and other technologies; CVE-2022-39952, a remote code execution (RCE) bug in Fortinet FortiNAC; and CVE-2019-18935, an RCE in Progress Telerik UI for ASP.NET AJAX. Other threat actors have exploited these bugs as well. CVE-2022-40684, for instance, is a flaw that a likely China-backed threat actor used in a widespread cyber espionage campaign dubbed “Volt Typhoon,” targeting organizations across multiple critical sectors including government, manufacturing, communication, and utilities.

“Earth Lusca takes advantage of server vulnerabilities to infiltrate its victim’s networks, after which it will deploy a web shell and install Cobalt Strike for lateral movement,” Trend Micro said in its report. “The group intends to exfiltrate documents and email account credentials, as well as to further deploy advanced backdoors like ShadowPad and the Linux version of Winnti to conduct long-term espionage activities against its targets.”

Editorial Team

Editorial Team

Related Posts

How to Transfer Songs From Spotify to Apple Music
Protection

How to Transfer Songs From Spotify to Apple Music

August 30, 2025
Every Samsung Galaxy S25 Is on Sale for Labor Day
Protection

Every Samsung Galaxy S25 Is on Sale for Labor Day

August 30, 2025
The XGIMI MoGo 3 Pro Outdoor Projector Is Down to Its Lowest Price Ever
Protection

The XGIMI MoGo 3 Pro Outdoor Projector Is Down to Its Lowest Price Ever

August 29, 2025
Home Depot's Best Labor Day Sales on Landscaping Power Tools
Protection

Home Depot’s Best Labor Day Sales on Landscaping Power Tools

August 29, 2025
Samsung's 'The Frame' TVs Are on Sale for Labor Day
Protection

Samsung’s ‘The Frame’ TVs Are on Sale for Labor Day

August 29, 2025
Google Is Now Rolling Out an AI-Powered Duolingo Competitor
Protection

Google Is Now Rolling Out an AI-Powered Duolingo Competitor

August 29, 2025
Load More
Next Post
Intel Stock Slips as CFO Warns of Excess Data Center Chip Inventories

Intel Stock Slips as CFO Warns of Excess Data Center Chip Inventories

Popular News

  • Josh Garber

    How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • Why has it taken Plum almost a month to transfer £16,000 from my cash Isa to my bank?

    0 shares
    Share 0 Tweet 0
  • Infinidesk Is a Mac App That Lets You Create As Many Virtual Desktops As You Want

    0 shares
    Share 0 Tweet 0
  • Struggling British fashion brand sold to Manchester sportswear group

    0 shares
    Share 0 Tweet 0
  • Private credit market competition leading to need to ‘limit call protection’

    0 shares
    Share 0 Tweet 0

Latest News

Japanese Game Developer Gumi to Acquire 2.5 Billion Yen Worth of XRP

Japanese Game Developer Gumi to Acquire 2.5 Billion Yen Worth of XRP

August 30, 2025
0

Key NotesGumi's board approved purchasing 6 million XRP tokens worth $17 million between September 2025 and February 2026.The company positions...

Fright: Mounting fears that Labour will stage a tax raid on banks saw billions of pounds wiped off the values of the biggest lenders

Billions wiped off value of banks in Labour tax fright

August 30, 2025
0

By JOHN-PAUL FORD ROJAS AND HUGO DUNCAN Updated: 06:37 EDT, 30 August 2025 --> --> --> Mounting fears that Labour...

World's first gene-edited horses are shaking up the genteel sport of polo

World's first gene-edited horses are shaking up the genteel sport of polo

August 30, 2025
0

World's first gene-edited horses are shaking up the genteel sport of polo

Client Challenge

Client Challenge

August 30, 2025
0

Client Challenge JavaScript is disabled in your browser. Please enable JavaScript to proceed. A required part of this site couldn’t...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.