Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Trend Micro tracked Earth Longzhi, a suspected APT41 subgroup, in a campaign targeting organizations in the Philippines, Thailand, Taiwan, and Fiji from December 2022 through March 2023. Its reporting describes a layered intrusion involving access to public-facing servers, a web shell, DLL sideloading, and techniques to disrupt security products. This is historical reporting, not evidence that the activity is continuing today.

What is Earth Longzhi, and how is it linked to APT41?

Trend Micro tracks Earth Longzhi as an APT41 subgroup. Dark Reading likewise describes it as a suspected subgroup; the attribution should be understood as a tracking assessment, not independently proven identity. Trend Micro reported that the activity resumed after a dormant period.

Where did the campaign operate?

Trend Micro’s campaign summary covers activity from December 2022 through March 2023. Samples indicated targeting of organizations in four locations and across four sectors:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Dimension Reported scope
Countries or territories Philippines, Thailand, Taiwan, and Fiji
Sectors Government, healthcare, technology, and manufacturing

Vietnamese- and Indonesian-language documents embedded in or used as decoys led researchers to infer that Vietnam and Indonesia might be targets in a later wave. Those artifacts were not confirmation of attacks or victims in either country.

What techniques did Earth Longzhi use?

The reporting describes multiple stages and defensive-evasion methods. It does not establish that every tool appeared in every incident.

Public-facing servers and a web shell

Dark Reading reported that the group targeted internet-facing IIS and Microsoft Exchange servers as entry points. After gaining access, it used the Behinder web shell to gather information and download additional malware. The sources contrast this route with phishing as a preferred way in, but do not establish that phishing never occurred.

DLL sideloading and malware delivery

The reported operation disguised malicious code as MpClient.dll, allowing legitimate Windows Defender binaries to load it through DLL sideloading. Dark Reading identifies Croxloader as a Cobalt Strike loader. These details describe reported campaign techniques; they should not be read as a claim that every target received the same payload.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Disrupting security tools

Trend Micro highlighted an IFEO-based technique it named “stack rumbling,” intended to disrupt security products. Dark Reading also identifies SPHijacker as an anti-detection tool. The reports describe defense evasion alongside the intrusion methods, rather than a single uniform sequence that can be assumed in every case.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What does the reporting mean for defenders?

The sources provide technique-level context, not a complete incident-response playbook. Their concrete defensive recommendation is to keep internet-facing systems patched and updated. James Lively, endpoint security research specialist at Tanium, told Dark Reading: “potential targets need to ensure that everything in their environment, especially public facing to the Internet, is fully patched and updated,” Patching is an important baseline, not a guarantee against intrusion.

Lively also told Dark Reading: “These methods are not overly novel and sophisticated,” followed by, “However, the knowledge, understanding, and tradecraft required to use them efficiently and accurately is.” His observation distinguishes the individual techniques from the skill required to combine and use them effectively.

Sources and scope

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.