Apr 25, 2025
Cyware Daily Threat Intelligence, April 25, 2025
An APT group with deep roots in Southeast Asia is quietly siphoning data through everyday cloud platforms. Earth Kurma has been active since late 2020, targeting government and telecom entities across the Philippines, Vietnam, Thailand, and Malaysia. Its extensive toolkit enables credential theft, stealthy surveillance, and Dropbox-based exfiltration.
One patch, two problems. Microsoft’s fix for CVE-2025–21204 may have closed a privilege escalation bug but it opened the door to a DoS vulnerability. By creating junction points, non-admin users can block future Windows updates from installing. There’s no fix yet, and unless the rogue junction is manually removed, security updates will fail silently.
Logos, lures, and lies - the Power Parasites campaign is using all three. Fraudsters are impersonating global energy brands to scam victims in Bangladesh, Nepal, and India through fake jobs and investment offers. With over 150 domains and active Telegram and YouTube promotion, the scheme blends fake onboarding forms with identity theft and financial fraud, all under the guise of renewable energy.