In 2023, a new cyberespionage campaign by a group we named Earth Estries was identified, indicating activity since at least 2020. Notably, similarities emerged between Earth Estries' tactics and those of the advanced persistent threat (APT) group, FamousSparrow. The tools and techniques used suggest the involvement of highly skilled threat actors wielding advanced resources, employing numerous backdoors and hacking tools to great effect, targeting organizations in the government and technology industries based in the Philippines, Taiwan, Malaysia, South Africa, Germany, and the US. In this topic, we discuss our detailed findings and technical analysis, including some backgrounds about Earth Estries and their motivations, attack methods and tools, C&C infrastructures, victimology and attribution.
TOPIC / TRACK
Threat Research Forum
LOCATION
Taipei Nangang Exhibition Center, Hall 2
7F 701B
LEVEL
Intermediate Intermediate sessions focus on cybersecurity architecture, tools, and practical applications, ideal for professionals with a basic understanding of cybersecurity.
SESSION TYPE
Breakout Session
LANGUAGE
English
SUBTOPIC
APT
Advanced Threat
Threat Intelligence
CYBERSEC 2024 uses cookies to provide you with the best user experience possible. By continuing to use this site, you agree to the terms in our Privacy Policy 。