Skip to content

Latest commit

 

History

History

Earth Wendigo

Folders and files

NameName
Last commit message
Last commit date

parent directory

..
 
 
 
 

NAME:
Earth Wendigo

Alias
Earth Wendigo

Description:
We discovered a new campaign that has been targeting several organizations — including government organizations, research institutions and universities in Taiwan — since May 2019, aiming to exfiltrate emails from targeted organizations via the injection of JavaScript backdoors to a webmail system that is widely-used in Taiwan.
Earth Wendigo uses typical spear-phishing techniques to initiate their attack, the threat actor also uses many atypical techniques to infiltrate the targeted organizations, such as the use of mail signature manipulation and Service Worker infection.

References:
https://www.trendmicro.com/en_us/research/21/a/earth-wendigo-injects-javascript-backdoor-to-service-worker-for-.html