Earth Minotaur
Earth Minotaur is a Chinese threat activity cluster tracked by Trend Micro. Reporting directly attributes to it the use of the MOONSHINE exploit kit and development/use of the DarkNimbus Android backdoor, also referred to as DarkNights in some reporting. Earth Minotaur primarily targets Tibetan and Uyghur communities, using social engineering messages in instant messaging applications, especially WeChat, to lure victims to malicious links. MOONSHINE attack links can masquerade as legitimate content, redirect victims back to benign pages after exploitation, and target vulnerable Chromium-based browsers and Tencent Browser Server components in Android applications, including WeChat. Reported MOONSHINE exploitation targeted multiple known Chromium vulnerabilities and was assessed as still under active development. In observed chains, successful exploitation installed a trojanized XWalk component containing DarkNimbus. DarkNimbus has Android and Windows variants; the Android variant supports extensive surveillance and data theft, including device, communications, location, file, screenshot, photo, recording, and foreground messaging-app conversation collection, while the Windows variant supports host profiling, installed software enumeration, file collection, browsing history theft, screenshots, keystroke capture, clipboard theft, shell execution, and browser credential theft. Cisco Talos also linked Earth Minotaur to the DKnife gateway-monitoring/adversary-in-the-middle framework and noted overlap with tooling also used by the China-aligned APT group TheWizards. Content also states DarkNimbus developed by Earth Minotaur was later used by TheWizards. Known alias directly mentioned in the content: DarkNights (for DarkNimbus).
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇨🇳 China
Where they're from
Attributed origin per open-source reporting.
- CN
Tradecraft
18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Associated vulnerabilities
9 CVEs this actor has used in observed campaigns. 9 of them exploited in the wild.
Vulnerability Targeted Version CVE-2016-1646 Chrome 39~49
Vulnerability Targeted Version CVE-2016-5198 Chrome 50
Vulnerability Targeted Version CVE-2017-5030 Chrome 51~55
Vulnerability Targeted Version CVE-2017-5070 Chrome 56~58
Vulnerability Targeted Version CVE-2018-17463 Chrome 68~69
4 more CVEs tied to this actor tracked in Mallory.
Observables
11 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Surveillance-focused cluster using the MOONSHINE exploit kit to deliver DarkNimbus backdoor to Android/Windows, targeting Tibetan and Uyghur communities (WeChat-focused per content).
China-nexus activity cluster associated with operating the DKnife adversary-in-the-middle/gateway-monitoring framework since at least 2019, leveraging router/edge-device implants for deep packet inspection, traffic manipulation, credential theft, DNS hijacking, and malware delivery (including backdoors).
China-nexus activity cluster linked to MOONSHINE exploit kit and the DarkNimbus backdoor; associated monitoring led to discovery of the DKnife AitM/gateway-monitoring framework.
Referenced as the developer of the DarkNimbus backdoor (deployed by TheWizard per the content).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.