Earth Lusca
MITRE ATT&CK: G1006 View on attack.mitre.org
Aliases: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX, FISHMONGER, BRONZE UNIVERSITY, AQUATIC PANDA, Red Dev 10, RedHotel, BountyGlad, Red Scylla, Earth Lusca
- First seen
- 2019-04-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Related IoCs
- 33 (31 malicious)
- Last IoC activity
- 2026-09-01 20:36:05
- Profile updated
- 2026-07-07 12:32:40
Targeted industries: government-and-public-sector media-and-entertainment education-and-nonprofits technology-and-telecommunications healthcare-and-pharmaceutical financial-services
Targeted regions: country_code:au country_code:cn country_code:hk country_code:mn country_code:np country_code:ph country_code:tw country_code:th country_code:vn country_code:ae country_code:ng country_code:de country_code:fr country_code:us
Context
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
Recent IoC activity
31 malicious indicators in Maltiverse are attributed to Earth Lusca (G1006). The 20 most recently updated:
Detection coverage
- 159 YARA rules
- 841 Sigma rules
Malware & tools used
- Steganography (attack-pattern)
- Upload Malware (attack-pattern)
- SSH Authorized Keys (attack-pattern)
- DCSync (attack-pattern)
- Visual Basic (attack-pattern)
- Drive-by Compromise (attack-pattern)
- Remote System Discovery (attack-pattern)
- Web Services (attack-pattern)
- JavaScript (attack-pattern)
- Exploitation of Remote Services (attack-pattern)
- Match Legitimate Resource Name or Location (attack-pattern)
- Deobfuscate/Decode Files or Information (attack-pattern)
- Domains (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Print Processors (attack-pattern)
- PowerShell (attack-pattern)
- Python (attack-pattern)
- Process Discovery (attack-pattern)
- Scheduled Task (attack-pattern)
- DLL (attack-pattern)
- Modify Registry (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- LSASS Memory (attack-pattern)
- Mshta (attack-pattern)
- Domain Trust Discovery (attack-pattern)
Related threat objects
- FishMedley (threat-actor)
Reports & references
- pwc.com — Yir Cyber Threats Report Download (report)
- Microsoft — Rwmfii (report)
- hello.global.ntt — The Operations Of Winnti Group (report)
- Trend Micro — Technical Brief Delving Deep An Analysis Of Earth Lusca Operations (report)
- recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
- media-exp1.licdn.com — 1639591145314 (report)
- sentinelone.com — Sentinelone Sentinellabs Shadowpad Wp V2 (report)
- pwc.co.uk — Chasing Shadows (report)
- CrowdStrike — Overwatch Exposes Aquatic Panda In Possession Of Log 4 Shell Exploit Tools (report)
- decoded.avast.io — Backdoored Client From Mongolian Ca Monpass (report)
- go.recordedfuture.com — Cta 2023 0808 (report)
- Kaspersky — 105127 (report)
- Kaspersky — 103517 (report)
- ncsc.gov.uk — Ncsc Mar Jolly Jellyfish (report)
- pwc.com — 2022 Year In Retrospect Report (report)
- youtube.com — Watch (report)
- ESET — Operation Fishmedley (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- MITRE ATT&CK — G1006 (report)
- recordedfuture.com — Chinese Group Tag 22 Targets Nepal Philippines Taiwan (report)
Attributed from
- Citrine Sleet Chromium Zero-Day Exploit Activity (CVE-2024-7971) (campaign)
External references
- mitre-attack — G1006
- Charcoal Typhoon
- ControlX
- CHROMIUM
- TAG-22
- TrendMicro EarthLusca 2022
- Recorded Future TAG-22 July 2021
- Recorded Future RedHotel August 2023
- Microsoft Threat Actor Naming July 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy