Trend Micro identified more than 200 victims in Earth Preta cyberespionage activity it analyzed from 2022, with organizations across multiple sectors and regions affected. The figure counts identified victims—not every organization the operators may have tried to target—and the reporting does not establish whether the activity is continuing today.
What Trend Micro reported
In an analysis published March 29, 2023, Trend Micro described attacks observed in 2022 as a coordinated effort by several Earth Preta operational groups to gather sensitive information. The researchers identified more than 200 victim organizations. This is a reported count of identified victims, not a verified census of all targets or attempted compromises. Trend Micro’s analysis is the primary source for the findings.
The identified organizations spanned transportation, government, manufacturing and fabrication, construction, education, finance, food production, border and immigration control, energy, and humanitarian groups. Trend Micro reported that more than half of identified victims were in Asia, followed by Africa, Europe, and the Middle East. Its cited summary does not provide exact regional counts or a percentage for Asia.
Who is Earth Preta?
SecurityWeek says Earth Preta is also known as Mustang Panda, RedDelta, and TA416. The publication describes the group as believed to operate on behalf of the Chinese government; this is an attributed assessment, not an independently established fact. SecurityWeek’s March 29, 2023 report summarizes Trend Micro’s findings.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
How the reported operational groups differed
Trend Micro distinguished three operational subgroups by their reported techniques. The available reporting provides only limited information about each group’s typical sector or geographic pattern, so it does not support a complete group-by-sector map.
| Group | Reported access, execution, or persistence methods | Reported exfiltration or targeting detail |
|---|---|---|
| 724 | Customized USB storage devices for initial access; sideloading with Adobe CEF Helper for persistence. | The cited summary does not state an exfiltration method or a specific sector or geographic pattern. |
| 1358 | Avast’s WSC DLL for sideloading; Windows Management Instrumentation (WMI) for execution; PlugX as a remote access tool. | USB drives were typically used for exfiltration. The cited summary does not specify a sector or geographic pattern. |
| 5171 | Adobe CEF Helper sideloading; Trend Micro reported that the group infected laptops with malicious code during routine work travel, then conducted more extensive exploitation and lateral movement. | USB-based exfiltration. The cited summary does not specify a sector or geographic pattern. |
These are observations attributed to Trend Micro; they do not mean that every subgroup used every method. The report said subgroups could overlap in targeting the same entity for similar objectives, while management-level coordination appeared limited. Trend Micro described a centralized development unit supplying tools to operational groups: “Earth Preta has a centralized development unit that produces the implants and tools, and disseminates them to other operational groups responsible for penetration and implantation. This is evident in the Earth Preta group as it appears that multiple sub-operational groups use the same toolset with different techniques.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the findings mean for organizations
The reported targets included organizations in sectors handling sensitive government, infrastructure, economic, and humanitarian work. The findings are relevant as historical threat awareness, particularly for organizations in the named sectors, but the reporting does not establish that a particular organization was compromised, that a particular product is vulnerable, or that the same techniques remain in use today.
Trend Micro characterized the operations as broad in reach and capable of targeting high-value institutions, and said collection priorities suggested attention to critical infrastructure and institutions with potential national and international impact. That is the vendor’s assessment, not an independently verified conclusion. The sources cited here do not provide a comprehensive defensive playbook or evidence of the campaign’s present-day operational status.
Quick Recap
Best Value
Rank #4
Rank #3
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

