Operation Earth Kitsune: Tracking SLUB’s Current Operations
ID: fc602b2d-c8c1-459e-ae21-87f0fb089ac2
STIX ID: report--fc602b2d-c8c1-459e-ae21-87f0fb089ac2
Threat Score
80/100
Uploaded: 2026-08-14
Published Date: 2020-10-19
Last Modified Date: 2020-10-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Earth Kitsune is an active, targeted espionage campaign documented by Trend Micro that compromises GNUBOARD‑based watering‑hole websites (targeting the Korean diaspora), weaponizes multiple patched/known browser vulnerabilities (including CVE‑2019‑5782 and CVE‑2020‑0674) to deliver a PowerShell/ DLL-based dropper, and deploys three custom malware families (SLUB, dneSpy, agfSpy). The SLUB variant evolved to use self‑hosted Mattermost as C2 to create per‑host channels, exfiltrate system data and screenshots, and manage infected hosts; the report includes analysis of shellcode, dropper behavior, security‑product checks, Mattermost API abuse, IoCs, and attacker operational details.
