Earth Longzhi — APT Profile

Trend Micro introduced Earth Longzhi in November 2022 as a previously undocumented cell operating under the APT41 umbrella, tracing two campaign waves between May 2020 and June 2022 that hit healthcare, government, infrastructure, banking, aviation, defence and insurance targets across Taiwan, Ukraine, China, Malaysia, Indonesia, Pakistan and Thailand. The subgroup went quiet for roughly half a year before Trend Micro reported a fresh round of intrusions in May 2023 against government, healthcare, technology and manufacturing organisations in Taiwan, Fiji, Thailand and the Philippines. Its tradecraft centres on bespoke Cobalt Strike loaders such as Croxloader, supported by Mimikatz and the BEHINDER web shell. Earth Longzhi is best known for SPHijacker, a purpose-built anti-security utility that, per Trend Micro's May 2023 analysis, terminates endpoint agents through a vulnerable Zemana driver and separately stops them starting at all by abusing Image File Execution Options — a denial-of-service trick the researchers named stack rumbling. Kaspersky also folded the group into its survey of APT activity against industrial organisations in the second half of 2022.

Also tracked as

SnakeCharmer

Vendor research

Countries linked to this actor

Read the full analysis on IntelFusions