Earth Naga is a China-aligned advanced persistent threat group assessed to operate in collaboration with other Chinese-speaking intrusion clusters. It has been linked operationally to a broader ecosystem of China-nexus actors through shared tooling and a reported access-brokering relationship with Earth Estries. In that model, Earth Estries is assessed to obtain initial access and pass victim environments to Earth Naga for follow-on exploitation, indicating a specialized division of labor within a small circle of cooperating operators. Earth Naga has been associated with campaigns targeting government agencies, including activity affecting Southeast Asia. Reporting also links it to tooling overlap with UAT-8302, a China-nexus cluster that targeted government entities in South America and southeastern Europe, although the exact boundary between these clusters is not fully established. Malware and loaders associated with Earth Naga include Draculoader, and related China-aligned operations in this ecosystem have used backdoors and stagers such as NetDraft, CloudSorcerer, SNOWLIGHT, SNOWRUST, Deed RAT, and Zingdoor. Observed tradecraft across this activity set includes suspected exploitation of public-facing applications for initial access, extensive internal reconnaissance, automated scanning, credential extraction, lateral movement, deployment of custom backdoors, and establishment of persistent alternate access through proxying and VPN tunneling tools. The operational objective is consistent with long-term clandestine access to government and related organizations rather than disruptive or financially motivated activity.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat actor receiving initial access from Earth Estries for subsequent exploitation activity.
APT group referenced as using Draculoader and historically targeting government agencies in Southeast Asia and elsewhere.
China-aligned cyberespionage actor described collaborating with another China-aligned group via access-brokering (‘pass-as-a-service’) to enable continued exploitation; targets include government and telecommunications, with recent focus on retail and government-related orgs in APAC.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.