PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteiTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Earth Krahang, a cyber-espionage actor that researchers associate with Chinese state interests, compromised at least 48 government organizations, according to Trend Micro findings reported in March 2024. That figure is not the number of all its victims: SecurityWeek reported that another 49 government entities were targeted, while the wider investigation counted at least 70 compromised organizations across 23 countries and at least 100 other entities targeted across 35 countries.
What the 48-organization figure means
The number refers to government organizations reported as compromised—not simply scanned, sent phishing messages, or otherwise targeted. SecurityWeek’s March 19, 2024 coverage of Trend Micro’s findings distinguishes at least 48 compromised government organizations from 49 additional government entities targeted. The investigation’s wider totals were at least 70 organizations compromised across 23 countries and at least 100 other entities targeted across 35 countries. SecurityWeek’s report provides those figures.
Dark Reading’s March 18, 2024 account described 116 organizations targeted across 35 countries and at least 70 confirmed compromises. These are different reported counts, not a live tally: the articles summarize an investigation from 2024, and “targeted” does not mean an organization was breached. Dark Reading’s coverage gives its count and geographic summary.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Who Earth Krahang targeted
Government and foreign-affairs organizations were prominent targets, but the activity extended beyond government agencies. Reported victims also included organizations in education, telecommunications, logistics, finance, healthcare, manufacturing, and military sectors. Dark Reading described activity across Asia, the Americas, Europe, and Africa.
#1 Best Overall
Trend Micro reporting cited by SecurityWeek said 10 foreign-affairs organizations were compromised and five others targeted. The reporting also described one incident in which a compromised government email account sent a malicious attachment to roughly 800 accounts. The account’s legitimate origin did not make the attachment safe; the incident illustrates how attackers can exploit institutional trust to reach more recipients.
How the campaign reportedly gained access
Earth Krahang used multiple entry paths rather than relying on one exploit. Reports describe scanning internet-facing servers linked to potential targets, exploiting known vulnerabilities, sending spear-phishing attachments and URLs, and brute-forcing email credentials. Attackers also reportedly compromised government web servers and email accounts, allowing malicious infrastructure or messages to appear more credible.
Exploiting exposed servers
The reporting identified command-execution vulnerabilities in Openfire (CVE-2023-32315) and Oracle Web Applications Desktop Integrator (CVE-2022-21587). Dark Reading gave CVSS scores of 7.5 and 9.8, respectively, in its March 2024 coverage. Those scores are reported in that article; organizations should consult current vendor advisories and authoritative vulnerability records for affected versions and remediation guidance rather than assume every deployment is vulnerable.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesUsing email and trusted infrastructure
Phishing messages carried attachments or links, while brute-force attempts targeted email credentials. In other reported activity, compromised government servers hosted backdoors or helped distribute download links to other government entities. Trend Micro’s assessment, quoted by SecurityWeek, was that Earth Krahang “abuses the trust between governments to conduct their attacks.” A sender address or government domain alone therefore cannot establish that a message is authentic.
Rank #3
What happened after an intrusion
After gaining a foothold, the actor reportedly used SoftEther VPN, scheduled tasks for persistence, remote desktop, network scanning, credential extraction from memory, lateral movement, and privilege escalation. Reported tools included Cobalt Strike and custom backdoors called Reshell and XDealer; some intrusions also involved PlugX and ShadowPad.
Dark Reading characterized Reshell as an earlier backdoor and XDealer as a later tool with keylogging, screenshot capture, and clipboard-theft capabilities. These tools support follow-on access and surveillance; their presence in reporting does not mean every compromised organization encountered every tool.
Rank #4
What is known about Earth Krahang’s links
Trend Micro identified overlaps in infrastructure and an initial backdoor that connected Earth Krahang’s activity with Earth Lusca. The vendor also said Earth Krahang could be another penetration team associated with I-Soon, drawing in part on leaked company documents. These are attributed researcher assessments and suspected connections, not definitive proof of a formal organizational structure or government direction. The reviewed reports do not provide a complete, independently verified victim list or establish the patch status of every affected system.
How government organizations can reduce risk
The reported attack paths point to several practical control areas. None is a guarantee, and the coverage does not establish a single product as a solution.
Best Value
- Train people to spot social engineering. Explain how spear-phishing works, and encourage staff to verify unusual requests or attachments through a separate trusted channel—even when a message appears to come from a government colleague or partner.
- Strengthen email defenses. Use organizational processes and controls to scrutinize suspicious links and attachments, including those sent from accounts that may have been compromised.
- Reduce exposure on public-facing systems. Maintain an accurate inventory of internet-facing services and promptly apply relevant security updates. The reporting supports patching as a general defense; it does not show that every victim was compromised because a system went unpatched.
- Limit movement inside the network. Segmentation can make it harder for an intruder to move from one system or unit to another after gaining access.
- Monitor for unusual access and traffic. Look for abnormal authentication, remote-access use, network scanning, or data movement that does not fit normal operational patterns.
These measures address different stages: user education and email controls can reduce successful phishing, patching can close known weaknesses on exposed systems, and segmentation and monitoring can help constrain or detect activity after access. SecurityWeek’s report quotes Trend Micro urging organizations to educate employees and others involved with them about social-engineering attacks; Dark Reading likewise highlights patching, segmentation, and monitoring as defensive practices.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

