Earth Lusca
Also known as: TAG-22 · Charcoal Typhoon · CHROMIUM · ControlX
Overview
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
Naming & attribution
Earth Lusca is tracked under 5 names across the industry. It uses 44 documented ATT&CK techniques — more than 79% of the 174 groups tracked here.
| Name | First reported by |
|---|---|
| TAG-22 | INSIKT GROUP |
| Charcoal Typhoon | Microsoft |
| CHROMIUM | Microsoft |
| ControlX | Microsoft |
Distinctive techniques
Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.
-
T1547.012Print Processors — used by 1 of 174 groups -
T1098.004SSH Authorized Keys — used by 3 of 174 groups
Closest groups by technique overlap
Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.
- MuddyWater Iran — 29 shared techniques (35% overlap)
- Turla Russia — 23 shared techniques (26% overlap)
- APT-C-36 — 17 shared techniques (26% overlap)
- Threat Group-3390 China — 20 shared techniques (25% overlap)
- Mustang Panda China — 25 shared techniques (24% overlap)
- Magic Hound Iran — 24 shared techniques (24% overlap)
Targets
Covid-19 Research Organizations · Cryptocurrency · Education · Gambling Companies · Government Institutions · Media · Medical · Pro-democracy And Human Rights Political Organizations · Religious Organization · Telecommunications
Regions
Australia · China · France · Germany · Hong Kong · Japan · Mongolia · Nepal · Nigeria · Philippines · Taiwan · Thailand · United Arab Emirates · United States · Vietnam
Capabilities
- Exploitation of public-facing / client applications — ATT&CK T1190
- Custom malware/implant development — ATT&CK: 3 attributed custom malware families
TTPs — 44 techniques across 14 tactics
Reconnaissance
-
T1595.002Vulnerability Scanning
Resource Development
-
T1583.001Domains -
T1583.004Server -
T1583.006Web Services -
T1584.004Server -
T1584.006Web Services -
T1588.001Malware -
T1588.002Tool -
T1608.001Upload Malware
Initial Access
-
T1189Drive-by Compromise -
T1190Exploit Public-Facing Application -
T1566.002Spearphishing Link
Execution
-
T1047Windows Management Instrumentation -
T1053.005Scheduled Task -
T1059.001PowerShell -
T1059.005Visual Basic -
T1059.006Python -
T1059.007JavaScript -
T1204.001Malicious Link -
T1204.002Malicious File
Persistence
-
T1098.004SSH Authorized Keys -
T1543.003Windows Service -
T1547.012Print Processors
Privilege Escalation
-
T1548.002Bypass User Account Control
Stealth
-
T1027Obfuscated Files or Information -
T1027.003Steganography -
T1036.005Match Legitimate Resource Name or Location -
T1140Deobfuscate/Decode Files or Information -
T1218.005Mshta -
T1574.001DLL
Defense Impairment
-
T1112Modify Registry
Credential Access
-
T1003.001LSASS Memory -
T1003.006DCSync
Discovery
-
T1007System Service Discovery -
T1016System Network Configuration Discovery -
T1018Remote System Discovery -
T1033System Owner/User Discovery -
T1049System Network Connections Discovery -
T1057Process Discovery -
T1482Domain Trust Discovery
Lateral Movement
Collection
-
T1560.001Archive via Utility
Command and Control
-
T1090Proxy
Exfiltration
-
T1567.002Exfiltration to Cloud Storage
Tools & malware (9)
Mimikatz · PowerSploit · Tasklist · certutil · Cobalt Strike · Winnti for Linux · Nltest · NBTscan · ShadowPad
Reporting (3)
- RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale — Insikt Group
- How Microsoft names threat actors — Microsoft
- Delving Deep: An Analysis of Earth Lusca’s Operations — Chen, J., et al