← threatfilter.dev / all groups / Earth Lusca
Earth Lusca
Also known as: TAG-22 · Charcoal Typhoon · CHROMIUM · ControlX
Overview
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
Targets
Covid-19 Research Organizations · Cryptocurrency · Education · Gambling Companies · Government Institutions · Media · Medical · Pro-democracy And Human Rights Political Organizations · Religious Organization · Telecommunications
Regions
Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines · Taiwan · Thailand · United Arab Emirates · United States · Vietnam
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 44 techniques across 14 tactics
Reconnaissance
-
T1595.002Vulnerability Scanning
Resource Development
-
T1583.001Domains -
T1583.004Server -
T1583.006Web Services -
T1584.004Server -
T1584.006Web Services -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1189Drive-by Compromise -
T1190Exploit Public-Facing Application -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1059.006Python -
T1059.007JavaScript -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1098.004SSH Authorized Keys -
T1543.003Windows Service -
T1547.012Print Processors
Privilege Escalation
-
T1548.002Bypass User Account Control
Stealth
-
T1027Obfuscated Files or Information -
T1027.003Steganography -
T1036.005Match Legitimate Resource Name or Location -
T1140Deobfuscate/Decode Files or Information -
T1218.005Mshta -
T1574.001DLL
Defense Impairment
-
T1112Modify Registry
Credential Access
-
T1003.001LSASS Memory -
T1003.006DCSync
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1482Domain Trust Discovery
Lateral Movement
Collection
-
T1560.001Archive via Utility
Command and Control
-
T1090Proxy
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (9)
Mimikatz · PowerSploit · Tasklist · certutil · Cobalt Strike · Winnti for Linux · Nltest · NBTscan · ShadowPad
Reporting (3)
- RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale — Insikt Group
- How Microsoft names threat actors — Microsoft
- Delving Deep: An Analysis of Earth Lusca’s Operations — Chen, J., et al