Earth Minotaur
Earth Minotaur is a Chinese threat activity cluster tracked by Trend Micro and Cisco Talos. The group is linked to the MOONSHINE exploit kit and the DarkNimbus Android backdoor, also referred to as DarkNights. Reporting states that Earth Minotaur has targeted primarily Tibetan and Uyghur communities. Cisco Talos identified the DKnife gateway-monitoring and adversary-in-the-middle framework while monitoring Earth Minotaur; DKnife has been used since at least 2019, runs as seven Linux-based implants on routers and edge devices, and supports deep packet inspection, traffic manipulation, DNS hijacking, credential harvesting from Chinese email services via POP3/IMAP decryption, and hijacking of binary downloads and Android application updates to deliver malware including ShadowPad and DarkNimbus. Multiple sources also note links between Earth Minotaur and the China-aligned APT group TheWizards through shared or related tooling: DarkNimbus is described as developed by Earth Minotaur and also used by TheWizards, and Cisco Talos reported Earth Minotaur as linked to tools also associated with TheWizards. Known aliases directly mentioned in the content for Earth Minotaur tooling include DarkNimbus/DarkNights for the backdoor; no additional direct aliases for the actor itself are provided.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
4 malware families attributed to this actor across reporting.
Recent activity
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Surveillance-focused cluster using the MOONSHINE exploit kit to deliver DarkNimbus backdoor to Android/Windows, targeting Tibetan and Uyghur communities (WeChat-focused per content).
China-nexus activity cluster associated with operating the DKnife adversary-in-the-middle/gateway-monitoring framework since at least 2019, leveraging router/edge-device implants for deep packet inspection, traffic manipulation, credential theft, DNS hijacking, and malware delivery (including backdoors).
China-nexus activity cluster linked to MOONSHINE exploit kit and the DarkNimbus backdoor; associated monitoring led to discovery of the DKnife AitM/gateway-monitoring framework.
Referenced as the developer of the DarkNimbus backdoor (deployed by TheWizard per the content).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.