Earth Longzhi is a China-linked cyberespionage threat group assessed to be a subgroup or sub-cluster of APT41. The group has been active since at least 2020 and has been associated with campaigns across Taiwan and other Asia-Pacific countries, with targeting that has included government, health care, infrastructure, banking, defense, aviation, insurance, and urban development organizations. It has also been linked through infrastructure and tradecraft overlaps to later intrusion activity in Southeast Asia, including operations against government and public-service entities. Earth Longzhi is primarily assessed as an espionage actor aligned with Chinese state interests. The group is known for heavy use of customized Cobalt Strike loaders and post-exploitation tooling. Reported loaders include Symatic, CroxLoader, BigpipeLoader, MultiPipeLoader, and OutLoader, alongside broader use of Cobalt Strike and other open-source or commodity frameworks in related activity. Earth Longzhi has repeatedly relied on DLL sideloading and DLL hijacking, process injection, anti-hooking, parent-process masquerading, named-pipe-based decryption, and decoy documents to evade detection and execute payloads. It has also exploited exposed applications and used spear-phishing with password-protected archives or download links for initial access. Post-compromise behavior includes reconnaissance, credential theft, persistence, lateral movement, and exfiltration. Reported capabilities include Active Directory mapping, password scanning, proxying, service-based persistence, scheduled-task creation, credential dumping, DCSync-style theft of directory secrets, browser-data theft, keylogging, and collection of sensitive documents and authentication material. Earth Longzhi has used standalone reimplementations of Mimikatz functionality, including modules for logon credential theft, backup key theft, and domain replication abuse. In related reporting, the group has also been associated with UAC bypass via IElevatedFactoryServer and high-privilege scheduled-task abuse. A notable aspect of Earth Longzhi tradecraft is aggressive defense evasion. The group has used Bring Your Own Vulnerable Driver techniques, including abuse of RTCore64.sys and other vulnerable drivers, to disable or degrade security tooling, terminate protected processes, unregister kernel callbacks used by AV and EDR products, and facilitate credential access. Researchers have also documented anti-analysis measures such as restoring or replacing hooked ntdll.dll code in memory before injection. Attribution to APT41 is based on victimology, shared malware characteristics, overlapping Cobalt Strike metadata, code similarities with other APT41-related clusters such as GroupCC, and recurring infrastructure patterns including Fastly CDN concealment and speed-test-themed command-and-control naming conventions. Earth Longzhi is also referenced in reporting as an APT41 subgroup whose infrastructure and techniques overlap with Cluster Charlie activity in the broader Crimson Palace espionage campaign.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 malware families attributed to this actor across reporting.
8 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
RTCore64.sys is a component of Afterburner. In 2019, this driver was assigned as CVE-2019-16098, which allows authenticated users to read/write any arbitrary address including kernel space. However, the outdated version of vulnerable driver still has a valid signature. As a result, the attacker can deliver the outdated version of the driver into the victim machine and abuse it for various purposes, such as for anti-antivirus or anti-EDR.
During the investigation of the second campaign, we collected multiple hacking tools used for privilege escalation (PrintNightmare and PrintSpoofer), credential dumping (custom standalone Mimikatz), and defense evasion (disablement of security products).
7 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a previously reported subgroup whose domain naming pattern matched infrastructure seen in Cluster Charlie activity.
Chinese subgroup of APT41 referenced because Cluster Charlie infrastructure overlaps with Earth Longzhi C2 IPs and speedtest-themed domain patterns.
Referenced as a previously reported subgroup whose domain naming pattern overlaps with infrastructure used in Cluster Charlie activity.
APT41 sub-cluster referenced in connection with prior DLL sideloading activity using the Vipre AV component (vetysafe.exe) to load a malicious DLL loader.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.