ATT&CKReferencesTrend Micro Earth Kasha Updates APR 2025

Trend Micro Earth Kasha Updates APR 2025

Hiroaki, H. (2025, April 30). Earth Kasha Updates TTPs in Latest Campaign Targeting Taiwan and Japan. Retrieved April 17, 2026.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software2

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1005
Data from Local System
MalwareUPPERCUT

UPPERCUT can upload files to the C2 from infected machines.

T1047
Windows Management Instrumentation
MalwareROAMINGHOUSE

ROAMINGHOUSE can use WMI to launch a legitimate executable later used to enable DLL sideloading.

T1059.003
Windows Command Shell
GroupMirrorFace

MirrorFace has used `cmd.exe` for malware execution, file discovery, and manual file manipulation.

T1070.004
File Deletion
GroupMirrorFace

MirrorFace has deleted directories containing malware and archives with files collected from the victim environment.

T1105
Ingress Tool Transfer
MalwareUPPERCUT

UPPERCUT can download and upload files to and from the victim’s machine.

T1113
Screen Capture
MalwareUPPERCUT

UPPERCUT can capture desktop screenshots in the PNG format and send them to the C2 server.

T1140
Deobfuscate/Decode Files or Information
MalwareROAMINGHOUSE

ROAMINGHOUSE can decode and drop a malicious ZIP file prior to execution.

T1204.001
Malicious Link
MalwareROAMINGHOUSE

ROAMINGHOUSE has been executed through luring victims into clicking links to download malicious ZIP files.

T1204.002
Malicious File
GroupMirrorFace

MirrorFace has lured victims into opening crafted Word, Excel, and SFX files for execution.

T1480
Execution Guardrails
MalwareROAMINGHOUSE

ROAMINGHOUSE can change its execution method to create a batch file in the startup folder that executes a legitimate executable if a McAfee product is detected.

T1518.001
Security Software Discovery
MalwareROAMINGHOUSE

ROAMINGHOUSE can identify McAfee applications on compromised hosts and change its execution method if one is detected.

T1548.002
Bypass User Account Control
MalwareUPPERCUT

UPPERCUT contains functionality to bypass UAC.

T1566.002
Spearphishing Link
GroupMirrorFace

MirrorFace has embedded OneDrive URLs in emails leading to malicious file installation.

T1566.002
Spearphishing Link
MalwareROAMINGHOUSE

ROAMINGHOUSE has been distributed through phishing emails containing malicious OneDrive links.

T1568.002
Domain Generation Algorithms
MalwareHiddenFace

HiddenFace has used dynamic domain generation algorithms in C2.

T1572
Protocol Tunneling
MalwareHiddenFace

HiddenFace can hide its IP lookup by using DNS over HTTPS (DoH) for C2.

T1573.001
Symmetric Cryptography
MalwareUPPERCUT

Some versions of UPPERCUT have used the hard-coded string “this is the encrypt key” for Blowfish encryption when communicating with a C2. Later versions have hard-coded keys uniquely for each C2 address. UPPERCUT has also used custom ChaCha20, XOR, and LZO algorithms for C2 communication.

T1574.001
DLL
MalwareROAMINGHOUSE

ROAMINGHOUSE can use a legitimate EXE to sideload a malicious DLL named JSFC.dll. ROAMINGHOUSE has also used ScnCfg32.exe to sideload vsodscpl.dll to enable UPPERCUT execution.

T1678
Delay Execution
MalwareUPPERCUT

UPPERCUT can use a sleep function to delay execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.