Earth Baxia is a cyber espionage group targeting government organizations in the Asia-Pacific region, particularly Taiwan, through spear-phishing and exploiting the GeoServer vulnerability (CVE-2024-36401). Their attacks involve deploying customized Cobalt Strike payloads and a new backdoor called EAGLEDOOR, which supports multiple communication protocols for data exfiltration. Organizations must enhance their cybersecurity measures to defend against these sophisticated threats.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox