Earth Kurma — APT Profile
Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advanced custom malware, including rootkits like KRNRAT and MORIYA, and utilize cloud storage services for exfiltration. Their toolsets include TESDAT and SIMPOBOXSPY, and they demonstrate adaptive TTPs and complex evasion techniques. Attribution overlaps with other APT groups, but distinct attack patterns warrant their separate designation.
Tools & malware
- Cobalt Strike Framework
- DMLOADER Loader
- DUNLOADER Loader
- FRPC Tool
- ICMPinger Tool
- KMLOG Stealer
- KRNRAT Backdoor
- LADON Framework
- MORIYA Backdoor
- NBTSCAN Tool
- ODRIZ Tool
- SIMPOBOXSPY Tool
- TESDAT Loader
- WMIHACKER Tool
Vendor research
Countries linked to this actor
Read the full analysis on IntelFusions