/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Trend Micro researchers detail Earth Krahang, a China-linked APT campaign that has breached 70 organizations in 23 countries and is potentially linked to I-Soon

A sophisticated hacking campaign attributed to a Chinese Advanced Persistent Threat (APT) group known as 'Earth Krahang …

BleepingComputer Bill Toulas

Context & Ripple Effects

Earth Krahang adds to a documented sequence of China-linked campaigns aimed across borders: Trend Micro previously described Earth Lusca targeting government agencies with new Linux malware, while Microsoft reported compromises of critical-infrastructure organizations across US industries in a separate state-sponsored campaign.

The reported scale—70 organizations in 23 countries—makes this a useful case for defenders tracking recurring, geographically broad espionage activity. The possible I-Soon connection remains unconfirmed, so it should not be treated as attribution.

First-order effects

  • Organizations identified in or matching the campaign’s targeting profile must assess exposure to Earth Krahang’s tooling and techniques, while Trend Micro’s report gives security teams new material for detection and investigation.
  • The report increases scrutiny of a China-linked actor operating across 23 countries; the suggested I-Soon relationship remains a lead rather than an established fact.

Second-order effects

  • Security teams and providers will need to correlate this campaign with other China-linked intrusion activity, including earlier attempts to exploit widely deployed Citrix and Zoho products across more than 20 countries.
  • The breadth of affected organizations raises the value of cross-border threat-intelligence sharing, since isolated indicators may otherwise obscure a coordinated campaign.

Third-order effects

  • If similar campaigns continue to surface across multiple sectors and jurisdictions, cyber defense will increasingly depend on ecosystem-level coordination rather than organization-by-organization response.
  • Repeated public reporting on long-running China-linked operations may sharpen expectations for evidence-based attribution, while keeping analytical separation between confirmed links and tentative associations.

The trend: Earth Krahang is another data point in the shift toward coordinated, intelligence-led defense against persistent cross-border cyberespionage campaigns.

Discussion

  • @campuscodi@mastodon.social Catalin Cimpanu on mastodon
    Trend Micro has linked a new Chinese APT group (Earth Krahang) to Chinese cyber contractor i-SOON  —  “Our previous report suggests Earth Lusca might be the penetration team behind the Chinese company I-Soon, which had their information leaked on GitHub recently. …
  • @trendmicrorsrch @trendmicrorsrch on x
    Trend Micro researchers have been observing a threat actor dubbed Earth Krahang. This APT group targets governments worldwide, using techniques like #spearphishing and brute force attacks to infiltrate networks and conduct espionage. Learn more here: ⬇️ https://research.trendmicr…
  • @thehellu Daniel Lunghi on x
    Our latest report on a CN #APT targeting tens of governments entities worldwide has been published 🥳 After monitoring it for a long time we realized it is likely related to the recent I-Soon company leaks. It discusses their TTPs and provides lots of IOCs https://www.trendmicro.c…
  • @virusbtn @virusbtn on x
    Trend Micro's @jspchc & @thehellu look into a new APT campaign, named Earth Krahang, targeting several government entities worldwide, with a strong focus on Southeast Asia. Their investigation identified multiple links between Earth Krahang & Earth Lusca. https://www.trendmicro.c…