Earth Preta’s Cyberespionage Campaign Hits Over 200

Earth Preta orchestrates a long-running cyberespionage operation involving multiple APT subgroups (724, 1358, 5171) with a centralized development unit, targeting a range of sectors and regions and expanding to maritime and government entities. The study highlights overlaps between groups, varied TTPs, and exfiltration methods that emphasize a blend of traditional intelligence tradecraft and cyber techniques. #EarthPreta #MustangPanda #PlugX #AdobeCEFHelper #Group724 #Group1358 #Group5171

Keypoints

  • Earth Preta (Mustang Panda) has been conducting cyberespionage activities since 2022 with a coordinated, multi-group structure and over 200 observed victims.
  • The operation shows a hierarchical setup: a central development unit creates implants/tools, distributed to subgroups responsible for penetration and implantation.
  • Operational groups manage their own entry methods and privilege escalation, indicating specialized, group-level expertise.
  • Targets shifted toward maritime/shipping, border control, and immigration agencies by late 2022, after prior focus on academia, energy, finance, and manufacturing sectors.
  • Victim overlaps across groups (724, 1358, 5171) suggest similar objectives and collection requirements, with limited evidence of direct coordination among groups.
  • Infection/exfiltration vectors include USB mass storage devices and “traveling laptop” exploits, with group-specific tooling and persistence techniques.

MITRE Techniques

  • [T1574] Hijack Execution Flow – DLL Side-Loading – Group 724 uses sideloading with Adobe CEF Helper to establish a persistent foothold in the user’s home directory. “Group 724 is possibly related to Earth Preta. The group utilizes sideloading with Adobe CEF Helper to establish a persistent foothold in the user’s home directory
  • [T1047] WMI – Windows Management Instrumentation – Avast WSC DLL sideloading leverages the WMI service to execute malicious code. “utilizing Avast’s WSC DLL for sideloading, a technique leveraging the Windows Management Instrumentation (WMI) service to execute malicious code.
  • [T1052] Exfiltration Over Physical Medium – Exfiltration via USB drives – Exfiltration methods utilized involve the use of USB sticks that are plugged in, enabling the PlugX tool to copy all collected data into a previously known and expected USB stick. “exfiltration methods utilized involve the use of USB sticks that are plugged in, enabling the PlugX tool to copy all collected data into a previously known and expected USB stick.

Indicators of Compromise

  • [File/Path] – Example file paths used by attackers – C:UsersXXXAAM UpdatesXXXAAM Updates.exe, and C:$RECYCLE.BINS-XXXXX$XXXH.pdf
  • [File/Pattern] – Common file-name patterns associated with Group 724 – AcroRD32XXX, AAM UpdatesXXX, AcrobatXXX
  • [Directory] – Persistence indicator tied to Recycle Bin usage – RECYCLERS.BIN
  • [Malware] – PlugX as a used remote access tool – PlugX
  • [Removable Media] – USB mass storage devices used for exfiltration – USB drive/mass storage device

Read more: https://www.trendmicro.com/en_us/research/23/c/earth-preta-cyberespionage-campaign-hits-over-200.html