Skip to content

Reported operators

Threat actors

1 named in public reporting
Salt Typhoon

HemiGate(Earth Estries) • taskhask.doc Encrypted Dracu Loader • Decrypt and execute the internalized second payload HemiGate ... HemiGate vs. RatelS • Several code-level similarities and similarities in the communication implementation part

MITRE ATT&CK

HemiGate in ATT&CK

16 distinct techniques

Reporting

Research mentioning HemiGate

Aug 19
Trendai Security

The Rise of Collaborative Tactics Among China-aligned Cyber Espionage Campaigns | TrendAI (US)

Trend Micro and TrendAI reported that China-aligned espionage groups collaborated by passing live access to already-compromised networks between intrusion sets, a model Trend calls "Premier Pass-as-a-Service." In one cited case, Earth Estries breached a Southeast Asian government environment, deployed CrowDoor and related tooling, and then enabled follow-on activity tied to Earth Naga—also tracked as Flax Typhoon, RedJuliett, or Ethereal Panda—including ShadowPad infrastructure. The reporting says this approach differs from traditional initial access brokerage because downstream operators appear to receive direct access to victim assets rather than just stolen credentials or footholds. The activity aligns with separate reporting that RedJuliett intensified cyber espionage against Taiwanese organizations through exploitation of internet-facing network perimeter devices, while Trend Micro described Earth Estries as conducting long-term intrusions across government, telecommunications, and information service providers in APAC, Taiwan, and NATO countries. Researchers said the cooperative model can place multiple China-linked actors in the same intrusion chain or even the same process flow, complicating attribution and incident response, and they highlighted exploitation of Citrix devices including CVE-2025-5777 among the techniques used to gain or extend access.

Aug 14
Trendai Security

Game of Emperor: Unveiling Long Term Earth Estries Cyber Intrusions | TrendAI (US)

Trend Micro and TrendAI reported that Earth Estries, a China-linked espionage group active since at least 2020, compromised more than 20 organizations across the United States, Asia-Pacific, the Middle East, South Africa, and Southeast Asia. The intrusions primarily targeted government, telecommunications, and technology-sector organizations, with researchers linking the activity to prolonged campaigns against telecom providers and government networks. The group has been associated with overlaps in tradecraft and tooling seen in FamousSparrow and other Chinese APT activity, though researchers said some malware and infrastructure may reflect shared ecosystem resources rather than exclusive ownership. Researchers said Earth Estries gained initial access by exploiting public-facing systems, including Ivanti Connect Secure, Fortinet FortiClient EMS SQL injection flaws, Sophos Firewall code injection bugs, and the Microsoft Exchange ProxyLogon chain. After breaching servers and administrative accounts, the actors used PowerShell downgrade attacks, DLL sideloading, living-off-the-land binaries, Cobalt Strike, SMB, and WMIC for persistence and lateral movement, while deploying backdoors and implants such as Zingdoor, HemiGate, TrillClient, GHOSTSPIDER, SNAPPYBEE, DEMODEX, and MASOL RAT. Stolen documents and browser data were exfiltrated through public file-sharing services and SMTP, and the operators masked command-and-control traffic with techniques including Fastly CDN fronting and infrastructure patterns consistent with DNS tunneling.

Aug 30
Trend Micro Research

Earth Estries Targets Government, Tech for Cyberespionage

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.