Overview 3 indicators
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
| domain | 3 | G1006-domain.txt |
Techniques 44 ATT&CK
Open in ATT&CK Navigator → or download the layer (44 techniques, layer 4.5)
- T1003.001 LSASS Memory
- T1003.006 DCSync
- T1007 System Service Discovery
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1027 Obfuscated Files or Information
- T1027.003 Steganography
- T1033 System Owner/User Discovery
- T1036.005 Match Legitimate Resource Name or Location
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1059.006 Python
- T1059.007 JavaScript
- T1090 Proxy
- T1098.004 SSH Authorized Keys
- T1112 Modify Registry
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1190 Exploit Public-Facing Application
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1210 Exploitation of Remote Services
- T1218.005 Mshta
- T1482 Domain Trust Discovery
- T1543.003 Windows Service
- T1547.012 Print Processors
- T1548.002 Bypass User Account Control
- T1560.001 Archive via Utility
- T1566.002 Spearphishing Link
- T1567.002 Exfiltration to Cloud Storage
- T1574.001 DLL
- T1583.001 Domains
- T1583.004 Server
- T1583.006 Web Services
- T1584.004 Server
- T1584.006 Web Services
- T1588.001 Malware
- T1588.002 Tool
- T1595.002 Vulnerability Scanning
- T1608.001 Upload Malware
Software 9
Principal sources 3 reports
Ranked by how many of this actor's indicators each report brought in.
- 3recordedfuture.com/chinese-group-tag-22-targets-nepal-phil…
- 3github.com/Insikt-Group/Research/blob/master/Chine…
- 3otx.alienvault.com/pulse/60e81a24e8d59fbc73500085
Related groups 2
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 3 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
recordedfuture.com/chinese-group-tag-22-targets-nepal-phil… · github.com/Insikt-Group/Research/blob/master/Chine… · otx.alienvault.com/pulse/60e81a24e8d59fbc73500085
microsoftd.tk wikimedia.vip windowshostnamehost.club
Further reading 8
- attack.mitre.org/groups/G1006
- go.recordedfuture.com/hubfs/reports/cta-2023-0808.pdf
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- recordedfuture.com/research/chinese-group-tag-22-targets-n…
- trendmicro.com/content/dam/trendmicro/global/en/resear…
- otx.alienvault.com/pulse/60e81a24e8d59fbc73500085
- github.com/Insikt-Group/Research/blob/master/Chine…
- recordedfuture.com/chinese-group-tag-22-targets-nepal-phil…