HemiGate(Earth Estries) • taskhask.doc Encrypted Dracu Loader • Decrypt and execute the internalized second payload HemiGate ... HemiGate vs. RatelS • Several code-level similarities and similarities in the communication implementation part
Reported operators
Threat actors
1 named in public reportingMITRE ATT&CK
HemiGate in ATT&CK
16 distinct techniquesTechniques
16 techniquesReporting
Research mentioning HemiGate
The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns | TrendAI (US)
Trend Micro and TrendAI reported that China-aligned espionage groups collaborated by passing live access to already-compromised networks between intrusion sets, a model Trend calls "Premier Pass-as-a-Service." In one cited case, Earth Estries breached a Southeast Asian government environment, deployed CrowDoor and related tooling, and then enabled follow-on activity tied to Earth Naga—also tracked as Flax Typhoon, RedJuliett, or Ethereal Panda—including ShadowPad infrastructure. The reporting says this approach differs from traditional initial access brokerage because downstream operators appear to receive direct access to victim assets rather than just stolen credentials or footholds. The activity aligns with separate reporting that RedJuliett intensified cyber espionage against Taiwanese organizations through exploitation of internet-facing network perimeter devices, while Trend Micro described Earth Estries as conducting long-term intrusions across government, telecommunications, and information service providers in APAC, Taiwan, and NATO countries. Researchers said the cooperative model can place multiple China-linked actors in the same intrusion chain or even the same process flow, complicating attribution and incident response, and they highlighted exploitation of Citrix devices including CVE-2025-5777 among the techniques used to gain or extend access.
Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions | TrendAI (US)
Trend Micro and TrendAI reported that Earth Estries, a China-linked espionage group active since at least 2020, compromised more than 20 organizations across the United States, Asia-Pacific, the Middle East, South Africa, and Southeast Asia. The intrusions primarily targeted government, telecommunications, and technology-sector organizations, with researchers linking the activity to prolonged campaigns against telecom providers and government networks. The group has been associated with overlaps in tradecraft and tooling seen in FamousSparrow and other Chinese APT activity, though researchers said some malware and infrastructure may reflect shared ecosystem resources rather than exclusive ownership. Researchers said Earth Estries gained initial access by exploiting public-facing systems, including Ivanti Connect Secure, Fortinet FortiClient EMS SQL injection flaws, Sophos Firewall code injection bugs, and the Microsoft Exchange ProxyLogon chain. After breaching servers and administrative accounts, the actors used PowerShell downgrade attacks, DLL sideloading, living-off-the-land binaries, Cobalt Strike, SMB, and WMIC for persistence and lateral movement, while deploying backdoors and implants such as Zingdoor, HemiGate, TrillClient, GHOSTSPIDER, SNAPPYBEE, DEMODEX, and MASOL RAT. Stolen documents and browser data were exfiltrated through public file-sharing services and SMTP, and the operators masked command-and-control traffic with techniques including Fastly CDN fronting and infrastructure patterns consistent with DNS tunneling.