Earth Kurma is an espionage-focused advanced persistent threat group active since at least November 2020. It targets government and government-related telecommunications organizations in Southeast Asia, including the Philippines, Vietnam, Thailand, and Malaysia. Its operations emphasize credential theft, prolonged concealed access, and exfiltration of sensitive documents. Its country of origin and state sponsorship have not been established. Earth Kurma combines custom malware with open-source and commercial tools. It uses NBTSCAN, ICMPinger, LADON, FRPC, and WMIHACKER for reconnaissance, network discovery, and lateral movement, including remote command execution through WMI and SMB administrative shares. Its custom KMLOG keylogger captures credentials and keystrokes. DUNLOADER, TESDAT, and DMLOADER execute next-stage payloads in memory, including Cobalt Strike beacons. Reflective loading, obfuscation, and alternative shellcode-execution mechanisms help evade detection. The group deploys MORIYA and KRNRAT kernel-mode rootkits to maintain persistence and conceal malicious activity. MORIYA intercepts TCP traffic and injects decrypted payloads into legitimate Windows processes. KRNRAT supports process manipulation, file and network-traffic concealment, shellcode execution, and deployment of a memory-resident user-mode backdoor. Rootkit installation abuses legitimate Windows installation components. Document theft operations collect PDF and Microsoft Office documents and package them into password-protected archives. Earth Kurma stages stolen archives in Active Directory SYSVOL, leveraging Distributed File System Replication to make them accessible across domain controllers. SIMPOBOXSPY and ODRIZ upload stolen data to Dropbox and OneDrive, respectively. Tooling and code overlap with ToddyCat and Operation TunnelSnake, but neither is an established alias or attribution for Earth Kurma.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
APT targeting government and telecommunications in Southeast Asia; compromises vulnerable web servers, performs recon and lateral movement, maintains persistence with rootkits/backdoors/loaders, and exfiltrates data via PowerShell and legitimate cloud/collaboration services (OneDrive, Dropbox, Cisco Webex).
New APT targeting government and telecom sectors in Southeast Asia using custom malware, rootkits, and cloud services for exfiltration.
An espionage-focused group whose observed activity dates to November 2020. It targets Southeast Asian government and government-related telecommunications organizations, steals credentials, maintains persistent access using custom loaders and kernel-level rootkits, and exfiltrates documents through Dropbox and OneDrive. Initial access remains unconfirmed. Tooling overlaps with ToddyCat and Operation TunnelSnake do not establish common attribution.
Referenced in wider ASN sightings only; not connected directly to the investigated intrusion.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.