Earth Lusca

MITRE ATT&CK: G1006 View on attack.mitre.org

Aliases: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX, FISHMONGER, BRONZE UNIVERSITY, AQUATIC PANDA, Red Dev 10, RedHotel, BountyGlad, Red Scylla, Earth Lusca

First seen
2019-04-01 00:00:00
Origin
CN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Related IoCs
33 (31 malicious)
Last IoC activity
2026-09-01 20:36:05
Profile updated
2026-07-07 12:32:40

Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits technology-and-telecommunications healthcare-and-pharmaceutical financial-services

Targeted regions: country_code:au country_code:cn country_code:hk country_code:mn country_code:np country_code:ph country_code:tw country_code:th country_code:vn country_code:ae country_code:ng country_code:de country_code:fr country_code:us

Context

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.

Recent IoC activity

31 malicious indicators in Maltiverse are attributed to Earth Lusca (G1006). The 20 most recently updated:

TypeIndicatorUpdatedSources
hostname live.musicweb.xyz 2026-09-03 2
hostname obo.videocenter.org 2026-02-15 1
file sample aea823d6446fbf9059391125a9b7fceb9f433b846275d28dc5f433645984a683.exe 2026-01-27 2
hostname valorantcheatsboss.com 2025-12-19 2
file sample 7e8c6961a10c95a5d97aece92c2e2d974d63ede98196413cc0cf033f92084f53 2025-11-24 1
file sample 16c6558634759e6efd4581de60cc2050d99a53245c6abde3d38fc140204777e9 2025-10-27 1
file sample 2 2025-10-24 2
file sample bounty-26274900544419549 2025-10-24 2
file sample e252a54e441ea88aafa694259386afd002153481af25a5b7b2df46d17ac53fcc 2025-10-22 1
file sample c78767cb268589c7e3519f8643c7d7bc891ee3e8f8660f9340419af278ade263.exe 2025-07-12 2
file sample e54a6551dd6e290cbe53d9ceda9e6d2bf36c1010ee939f3192c97de6b5a2650c.exe 2025-02-14 2
hostname tech.learningstudy.xyz 2024-10-29 2
hostname backdoor.win64.shadowpad.as 2024-05-21 1
file sample dde04eaac96964e86b8734f67f3b6741505fdc5e177dd58e85da12a8120a44bf 2023-08-20 1
file sample f8c5feaae3f8e4bfb37edf4e05d1ee91797023bdf71e1c45ed2711861b300f37 2023-08-20 1
file sample c35b8514e3b2649e17c13fd9dc4796dbc52e38e054d518556c82e6df38ca4c1b 2023-08-20 1
file sample bdc6a2985a07ef3c5d2ef2a0eb53afdfdbf757bfa080e8b77ba4b47c1a99b423 2023-08-20 1
file sample 953e3ed35d84c4a7c4a599f65b2fbd6475b474e9b4bf85581255f1d81d2b5e4e 2023-08-20 1
file sample c1feef03663a9aa920a9ab4eb2ab7adadb3f2a60db23a90e5fe9b949d4ec22b6 2023-08-20 1
file sample 8b5e918595c27db3bcafd59a86045605837bc5843c938039852218d72cf2c253 2023-08-20 1

Detection coverage

  • 159 YARA rules
  • 841 Sigma rules

Malware & tools used

  • Steganography (attack-pattern)
  • Upload Malware (attack-pattern)
  • SSH Authorized Keys (attack-pattern)
  • DCSync (attack-pattern)
  • Visual Basic (attack-pattern)
  • Drive-by Compromise (attack-pattern)
  • Remote System Discovery (attack-pattern)
  • Web Services (attack-pattern)
  • JavaScript (attack-pattern)
  • Exploitation of Remote Services (attack-pattern)
  • Match Legitimate Resource Name or Location (attack-pattern)
  • Deobfuscate/Decode Files or Information (attack-pattern)
  • Domains (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Print Processors (attack-pattern)
  • PowerShell (attack-pattern)
  • Python (attack-pattern)
  • Process Discovery (attack-pattern)
  • Scheduled Task (attack-pattern)
  • DLL (attack-pattern)
  • Modify Registry (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • LSASS Memory (attack-pattern)
  • Mshta (attack-pattern)
  • Domain Trust Discovery (attack-pattern)

Related threat objects

Reports & references

  • pwc.com — Yir Cyber Threats Report Download (report)
  • Microsoft — Rwmfii (report)
  • hello.global.ntt — The Operations Of Winnti Group (report)
  • Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
  • recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
  • media-exp1.licdn.com — 1639591145314 (report)
  • sentinelone.com — Sentinelone Sentinellabs Shadowpad Wp V2 (report)
  • pwc.co.uk — Chasing Shadows (report)
  • CrowdStrike — Overwatch Exposes Aquatic Panda In Possession Of Log 4 Shell Exploit Tools (report)
  • decoded.avast.io — Backdoored Client From Mongolian Ca Monpass (report)
  • go.recordedfuture.com — Cta 2023 0808 (report)
  • Kaspersky — 105127 (report)
  • Kaspersky — 103517 (report)
  • ncsc.gov.uk — Ncsc Mar Jolly Jellyfish (report)
  • pwc.com — 2022 Year In Retrospect Report (report)
  • youtube.com — Watch (report)
  • ESET — Operation Fishmedley (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • MITRE ATT&CK — G1006 (report)
  • recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)

Attributed from

  • Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)

External references