Earth Baxia: A New Threat to APAC Governments

Red | Attack Report
Download PDF

Earth Baxia is a cyber espionage group targeting government organizations in the Asia-Pacific region, particularly Taiwan, through spear-phishing and exploiting the GeoServer vulnerability (CVE-2024-36401). Their attacks involve deploying customized Cobalt Strike payloads and a new backdoor called EAGLEDOOR, which supports multiple communication protocols for data exfiltration. Organizations must enhance their cybersecurity measures to defend against these sophisticated threats.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox