Earth_Wendigo__2021__trendmicro.com-Earth_Wendigo_Injects_JavaScript_Backdoor_for_Mailbox_Exfiltration.pdf
ID: 66aaa181-5358-4d2f-9606-ea27063b9398
STIX ID: report--66aaa181-5358-4d2f-9606-ea27063b9398
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2021-01-07
Last Modified Date: 2021-01-07
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Earth Wendigo is a targeted espionage campaign that has abused webmail XSS and Service Worker registration to implant JavaScript backdoors and establish WebSocket connections for automated mailbox exfiltration; victims include government, research, and university organizations in Taiwan and targeted activists. The report details infection/propagation techniques (spear-phishing, mail-signature poisoning, shortcut XSS), Service Worker credential theft, a WebSocket backdoor that issues get(URL) commands to read mail and attachments, additional Python-compiled Windows malware/shellcode loaders, and provides numerous IoCs (malicious domains and file hashes) and remediation guidance.
