Earth Kurma is an advanced persistent threat group conducting cyberespionage operations against government and telecommunications organizations in Southeast Asia. Activity attributed to the group has been observed since at least November 2020, with reporting highlighting sustained campaigns through 2024 and beyond. Its operations are characterized by long-term clandestine access, strategic intelligence collection, and a strong emphasis on data exfiltration. Earth Kurma primarily targets public-sector entities and government-related telecommunications organizations, with confirmed victim geography including the Philippines, Vietnam, Thailand, and Malaysia. The group’s tradecraft indicates a mature post-compromise capability set spanning reconnaissance, credential theft, lateral movement, persistence, defense evasion, and exfiltration. The actor uses a mix of custom malware and publicly available tools. Reported tooling includes loaders such as DUNLOADER, TESDAT, DMLOADER, and MMLOAD; exfiltration components such as SIMPOBOXSPY, ODRIZ, and SIMPOWEBEXSPY; a keylogger known as KMLOG; and rootkits and backdoors including KRNRAT and MORIYA. Earth Kurma has also deployed Cobalt Strike and used utilities such as NBTSCAN, ICMPinger, Ladon, FRPC, and WMIHACKER for internal discovery, movement, and operational support. A notable feature of Earth Kurma’s operations is its use of stealth-focused persistence and evasion mechanisms. The group has employed kernel-level rootkits to conceal activity and maintain access, including MORIYA, which intercepts network traffic and injects payloads into system processes, and KRNRAT, which supports process manipulation, file hiding, shellcode execution, traffic concealment, and backdoor functionality. Loaders are used to execute payloads in memory, and rootkit installation has involved living-off-the-land techniques and abuse of legitimate system components. Process injection into svchost.exe and reflective loading have also been reported. For collection and theft, Earth Kurma has used PowerShell and custom tooling to gather documents and compress them for staging. The group has exfiltrated data through legitimate cloud platforms, particularly Dropbox and Microsoft OneDrive, and has also used Cisco Webex-related channels in some operations. In some intrusions, it leveraged Active Directory Distributed File System Replication to synchronize staged archives across domain controllers before exfiltration. Credential harvesting has included keylogging. Operational overlaps have been noted with other espionage clusters, including similarities between MORIYA and tooling associated with Operation TunnelSnake, and overlap between SIMPOBOXSPY-related tradecraft and the ToddyCat cluster. However, attribution to those groups has not been established conclusively. Earth Kurma is best characterized as a distinct espionage-focused APT with sophisticated malware development, modular tooling, and strong operational security. Available reporting suggests likely state backing, but a specific sponsoring state has not been confirmed at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
7 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT targeting government and telecommunications in Southeast Asia; compromises vulnerable web servers, performs recon and lateral movement, maintains persistence with rootkits/backdoors/loaders, and exfiltrates data via PowerShell and legitimate cloud/collaboration services (OneDrive, Dropbox, Cisco Webex).
New APT targeting government and telecom sectors in Southeast Asia using custom malware, rootkits, and cloud services for exfiltration.
Referenced in wider ASN sightings only; not connected directly to the investigated intrusion.
Earth Kurma is conducting cyberespionage campaigns targeting government and telecommunications sectors in Southeast Asia, using custom malware, rootkits, and public cloud services for data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.