Earth Bluecrow is a suspected China-linked cyber espionage threat actor associated with long-running BPFDoor intrusions. The group has been observed targeting organizations in the communications, financial, and retail sectors across Asia and the Middle East, including activity affecting South Korea, Hong Kong, Myanmar, Malaysia, and Egypt. It has been linked to a breach of a South Korean telecommunications company in 2025. The actor is notable for use of BPFDoor, a stealth-oriented backdoor that leverages Berkeley Packet Filter functionality to conceal command-and-control activation and maintain covert access on compromised systems. Reporting indicates Earth Bluecrow has used a newer BPFDoor controller since at least 2021. The malware supports durable persistence, covert post-compromise access, lateral movement, and access to sensitive data inside victim environments, consistent with long-term intelligence collection objectives. Earth Bluecrow’s operations align with espionage-focused intrusion activity rather than financially motivated crime. Initial access mechanisms and specific exploited vulnerabilities in the referenced campaign remain under investigation, but the actor is associated with sustained post-exploitation tradecraft designed to evade detection and preserve long-term footholds in targeted enterprise networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Listed as a threat actor associated in the report’s aggregated section with exploitation activity around React2Shell (CVE-2025-55182) and related RSC/Next.js vulnerabilities.
Named in an aggregated list of actors associated with React2Shell (CVE-2025-55182) exploitation activity.
Earth Bluecrow is conducting long-term cyber espionage using BPFDoor backdoor, targeting communication, finance, and retail sectors in Asia and the Middle East.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.