Also known as: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX, FISHMONGER, BRONZE UNIVERSITY, AQUATIC PANDA, Red Dev 10, RedHotel, BountyGlad, Red Scylla, APT34, Earth Preta, Stately Taurus, APT28, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Red Moros, Othorene, Lotus Panda, Billbug
Earth Lusca is an advanced threat actor associated with China’s state‑level cyber capabilities. First identified in 2019, the group has conducted operations against a global portfolio of targets spanning government agencies, universities, media outlets, energy utilities, and defense contractors. Its campaigns combine low‑visibility initial access vectors such as watering holes using legitimate‑looking domains and compromised web services (GitHub, Google Drive) with targeted spearphishing that deploys decoy documents to deliver payloads. Operationally, Earth Lusca exhibits a layered approach: it leverages publicly available exploits (e.g., ZeroLogon CVE‑2020‑1472 against domain controllers and Microsoft Exchange/Glassfish vulnerabilities), engages credential dumping tools such as Mimikatz for DCSync or LSASS memory extraction, and uses privileged execution mechanisms including registry modification of the Print Processor entry to load malicious DLLs. After establishing footholds it deploys a suite of backdoors—most notably KTLVdoor (multiplatform), CrimsonRAT on Windows, and AndroRAT on Android—to maintain persistence, pivot laterally with Cobalt Strike, and exfiltrate data via cloud services like MEGA. The group’s technical footprint aligns closely with other Chinese APTs but remains distinguishable through its combination of print‑processor loading techniques and the broad exploitation of ZeroLogon. Earth Lusca’s campaigns reveal a methodical progression from initial compromise to credential acquisition, lateral expansion, data staging, and finally exfiltration over web services or encrypted channels. Defenders should treat Earth Lusca as a high‑priority threat for entities within the targeted sectors, particularly those operating on Windows infrastructures with Domain Controllers, exposed Exchange servers, or cloud‑oriented workflows.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Lusca is a Chinese state‑sponsored cyber espionage group active since at least 2019, using diverse delivery channels such as watering holes, spearphishing links, and exploitation of public‑facing applications. The actor targets a broad range of sectors—including government, critical infrastructure, academia, media, and defense—across more than fifty countries. Earth Lusca demonstrates sophisticated persistence mechanisms (e.g., KTLVdoor, CrimsonRAT) and exfiltration channels (cloud storage and remote services).
Goals & Targeting
Earth Lusca’s strategic objective centers on state‑driven intelligence gathering. By infiltrating institutions that hold politically and strategically sensitive information—such as defense ministries, critical‑infrastructure operators, research laboratories, media conglomerates, and academic collaborations—the group seeks to build a comprehensive knowledge base of rival national capabilities, scientific advances, and policy developments. The inclusion of Indian Army or civil‑society organizations in the campaign portfolio suggests a geopolitical focus on regional dynamics and power projection. The actor selects targets that provide actionable insights for broader intelligence missions, often prioritizing public‑sector entities to ensure high-value data while leveraging widespread global deployment capabilities to diversify risk.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Lusca demonstrates a consistent multi‑stage operational pattern that begins with low‑friction initial access via spearphishing links or watering holes, followed by exploitation of public vulnerabilities (ZeroLogon, Exchange/Glassfish). The actor then establishes persistence through registry modifications and print‑processor DLL loading, leverages advanced credential‑dumping and privilege escalation tools such as Mimikatz DCSync, and propagates lateral movement using Cobalt Strike. Data staging occurs on compromised hosts before exfiltration via cloud services (MEGA) or remote services. Past campaigns have revealed activity in at least 2022–2024, targeting over fifty countries across industrial, government, and academic sectors. The group’s tempo appears steady but adaptive, often aligning with regional geopolitical events.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The core behavioral profile (watering holes, spearphishing links, ZeroLogon exploitation, use of KTLVdoor and Mimikatz) is corroborated by multiple independent vendor reports and MITRE ATT&CK mapping, providing a high confidence level for those tactics. Attribution to the Chinese state remains consistent with observed infrastructure reuse patterns, yet some IOC specifics (domain names, internal backends) are less complete due to limited open‑source data. Overall confidence in the attack model is medium‑high; gaps persist around full persistence mechanisms outside of KTLVdoor and cross‑platform capabilities.
Red October
Cloud Atlas
No observed data linked yet.
67
Techniques
54
Tools
2
Campaigns
17
IOCs
0
Observed Data
15
Tactics