logo

Earth_Wendigo__2021__trendmicro.com-Earth_Wendigo_Injects_JavaScript_Backdoor_for_Mailbox_Exfiltration.pdf

ID: 66aaa181-5358-4d2f-9606-ea27063b9398

STIX ID: report--66aaa181-5358-4d2f-9606-ea27063b9398

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2021-01-07

Last Modified Date: 2021-01-07

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Earth Wendigo is a targeted espionage campaign that has abused webmail XSS and Service Worker registration to implant JavaScript backdoors and establish WebSocket connections for automated mailbox exfiltration; victims include government, research, and university organizations in Taiwan and targeted activists. The report details infection/propagation techniques (spear-phishing, mail-signature poisoning, shortcut XSS), Service Worker credential theft, a WebSocket backdoor that issues get(URL) commands to read mail and attachments, additional Python-compiled Windows malware/shellcode loaders, and provides numerous IoCs (malicious domains and file hashes) and remediation guidance.
Earth_Wendigo__2021__trendmicro.com-Earth_Wendigo_Injects_JavaScript_Backdoor_for_Mailbox_Exfiltration.pdf | Stixify