Tag: EAGLEDOOR Malware

Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware
News

Chinese Hackers Exploit GeoServer Flaw to Target APAC Nations with EAGLEDOOR Malware

By taking advantage of a newly patched severe security issue affecting OSGeo GeoServer GeoTools, a government agency in Taiwan and potentially other countries in the Asia-Pacific (APAC) region were targeted by a suspected advanced persistent threat (APT) that originated in China. Trend Micro discovered the intrusion activity in July 2024, and it has been linked to a threat actor known as Earth Baxia. According to researchers Ted Lee, Cyris Tseng, Pierre Lee, Sunny Lu, and Philip Chen, the targets appear to be primarily government agencies, telecommunications companies, and the energy industry in the Philippines, South Korea, Vietnam, Taiwan, and Thailand based on the phishing emails, decoy documents, and incident observations gathered. The discovery of lure documents in Simplifie...