NEW: Group Profiler — instant APT intel lookup. Try it →

Earth Lusca

G1006 China MITRE ATT&CK →

Also known as: TAG-22 · Charcoal Typhoon · CHROMIUM · ControlX

Overview

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.

Naming & attribution

Earth Lusca is tracked under 5 names across the industry. It uses 44 documented ATT&CK techniques — more than 79% of the 174 groups tracked here.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
TAG-22INSIKT GROUP
Charcoal TyphoonMicrosoft
CHROMIUMMicrosoft
ControlXMicrosoft

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1547.012 Print Processors — used by 1 of 174 groups
  • T1098.004 SSH Authorized Keys — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

  • MuddyWater Iran — 29 shared techniques (35% overlap)
  • Turla Russia — 23 shared techniques (26% overlap)
  • APT-C-36 — 17 shared techniques (26% overlap)
  • Threat Group-3390 China — 20 shared techniques (25% overlap)
  • Mustang Panda China — 25 shared techniques (24% overlap)
  • Magic Hound Iran — 24 shared techniques (24% overlap)

Targets

Covid-19 Research Organizations · Cryptocurrency · Education · Gambling Companies · Government Institutions · Media · Medical · Pro-democracy And Human Rights Political Organizations · Religious Organization · Telecommunications

Regions

Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines · Taiwan · Thailand · United Arab Emirates · United States · Vietnam

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1190
  • Custom malware/implant development — ATT&CK: 3 attributed custom malware families

TTPs — 44 techniques across 14 tactics

Reconnaissance

Resource Development

Execution

Persistence

Privilege Escalation

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Exfiltration

Tools & malware (9)

Mimikatz · PowerSploit · Tasklist · certutil · Cobalt Strike · Winnti for Linux · Nltest · NBTscan · ShadowPad

Reporting (3)