Earth KurmaEarth Kurma

Also known as: Earth Kurma

Known aliases
1

Profile

Earth Kurma is an APT group targeting government and telecommunications sectors in Southeast Asia, with a primary focus on data exfiltration. They employ advanced custom malware, including rootkits like KRNRAT and MORIYA, and utilize cloud storage services for exfiltration. Their toolsets include TESDAT and SIMPOBOXSPY, and they demonstrate adaptive TTPs and complex evasion techniques. Attribution overlaps with other APT groups, but distinct attack patterns warrant their separate designation.

Aliases· 1

Earth Kurma

References

  1. https://www.trendmicro.com/en_us/research/25/d/earth-kurma-apt-campaign.html

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
Earth Krahang
Actor
Earth Kapre
Actor
Earth Kitsune
Actor
Earth Naga
Actor
Earth Lamia
Actor
Earth Alux
Sourced from MISP-Galaxy Threat Actor cluster. Curated by Adam Lundqvist, Founder at SQUR.