Earth Wendigo — APT Profile

Earth Wendigo injects JavaScript backdoors into a webmail system widely used in Taiwan, exfiltrating emails from Taiwanese government organizations, research institutions, and universities since May 2019; the group operates from China. The threat actor also sent spear-phishing emails embedded with malicious links to multiple individuals, including politicians and activists, who support movements in Tibet, the Uyghur region, or Hong Kong.

Read the full analysis on IntelFusions