Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Lusca

Also known as: TAG-22, Charcoal Typhoon, CHROMIUM, ControlX, FISHMONGER, BRONZE UNIVERSITY, AQUATIC PANDA, Red Dev 10, RedHotel, BountyGlad, Red Scylla, APT34, Earth Preta, Stately Taurus, APT28, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND, Daggerfly, StormBamboo, ETHEREAL PANDA, Soft Cell, Alloy Taurus, Red Moros, Othorene, Lotus Panda, Billbug

Description

Earth Lusca is an advanced threat actor associated with China’s state‑level cyber capabilities. First identified in 2019, the group has conducted operations against a global portfolio of targets spanning government agencies, universities, media outlets, energy utilities, and defense contractors. Its campaigns combine low‑visibility initial access vectors such as watering holes using legitimate‑looking domains and compromised web services (GitHub, Google Drive) with targeted spearphishing that deploys decoy documents to deliver payloads. Operationally, Earth Lusca exhibits a layered approach: it leverages publicly available exploits (e.g., ZeroLogon CVE‑2020‑1472 against domain controllers and Microsoft Exchange/Glassfish vulnerabilities), engages credential dumping tools such as Mimikatz for DCSync or LSASS memory extraction, and uses privileged execution mechanisms including registry modification of the Print Processor entry to load malicious DLLs. After establishing footholds it deploys a suite of backdoors—most notably KTLVdoor (multiplatform), CrimsonRAT on Windows, and AndroRAT on Android—to maintain persistence, pivot laterally with Cobalt Strike, and exfiltrate data via cloud services like MEGA. The group’s technical footprint aligns closely with other Chinese APTs but remains distinguishable through its combination of print‑processor loading techniques and the broad exploitation of ZeroLogon. Earth Lusca’s campaigns reveal a methodical progression from initial compromise to credential acquisition, lateral expansion, data staging, and finally exfiltration over web services or encrypted channels. Defenders should treat Earth Lusca as a high‑priority threat for entities within the targeted sectors, particularly those operating on Windows infrastructures with Domain Controllers, exposed Exchange servers, or cloud‑oriented workflows.

Goals & Targeting

Targeted Sectors

Government
Education
Media
Telecommunications
Research
Defense
Financial services
Non profit
Healthcare
Energy
Manufacturing
Think tank
Critical infrastructure
Aerospace
Pharmaceutical
Aviation
Hospitality
Maritime
Transportation
Legal services
Information technology
Chemical
Retail
Gaming
Nuclear
Entertainment
Mining
Utilities
Oil gas
Construction

Targeted Countries / Regions

CN
US
RU
UA
AE
IL
TW
VN
PK
BY
IN
IR
JP
KR
PL
AU
SA
DE
TR
LB
KZ
GB
FR
IT
SG
NG
IQ
MX
ES
CA
RO
KP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 18 minutes ago

Executive Summary

Earth Lusca is a Chinese state‑sponsored cyber espionage group active since at least 2019, using diverse delivery channels such as watering holes, spearphishing links, and exploitation of public‑facing applications. The actor targets a broad range of sectors—including government, critical infrastructure, academia, media, and defense—across more than fifty countries. Earth Lusca demonstrates sophisticated persistence mechanisms (e.g., KTLVdoor, CrimsonRAT) and exfiltration channels (cloud storage and remote services).

Goals & Targeting

Earth Lusca’s strategic objective centers on state‑driven intelligence gathering. By infiltrating institutions that hold politically and strategically sensitive information—such as defense ministries, critical‑infrastructure operators, research laboratories, media conglomerates, and academic collaborations—the group seeks to build a comprehensive knowledge base of rival national capabilities, scientific advances, and policy developments. The inclusion of Indian Army or civil‑society organizations in the campaign portfolio suggests a geopolitical focus on regional dynamics and power projection. The actor selects targets that provide actionable insights for broader intelligence missions, often prioritizing public‑sector entities to ensure high-value data while leveraging widespread global deployment capabilities to diversify risk.

Enhanced Description

Key Capabilities

  • Watering hole attacks via legitimate-looking domains and compromised web servers, GitHub, and Google Drive
  • Spearphishing with malicious links that open decoy documents containing a malicious loader
  • Scanning public-facing servers for exploits such as Microsoft Exchange and Oracle Glassfish vulnerabilities
  • Exploiting the ZeroLogon vulnerability (CVE‑2020‑1472) against domain controllers to gain administrative access
  • Inserting malicious print‑processor DLLs via registry modification of the Print Processors entry in HKLM\\SYSTEM\\ControlSet001
  • Uploading exfiltrated data from victim networks to MEGA using the megacmd tool
  • Deploying KTLVdoor and other backdoors (Linux, Windows) for multiplatform persistence and lateral movement
  • Leveraging Mimikatz DCSync and credential‑dumping techniques for account takeover
  • Using Cobalt Strike for further lateral movement and post‑exploitation
  • Deploying CrimsonRAT on Windows systems as a persistent backdoor and AndroRAT on Android devices in occasional operations

MITRE ATT&CK Tactics

Initial Access
Reconnaissance and Discovery
Privilege Escalation
Credential Access
Execution
Defense Evasion
Persistence
Command & Control
Exfiltration
Lateral Movement

ATT&CK Techniques

T1003
T1003.001
T1003.006
T1007
T1016
T1018
T1027
T1027.003
T1033
T1046
T1047
T1049
T1053
T1053.005
T1057
T1059
T1059.001
T1059.005
T1059.006
T1059.007
T1090
T1098
T1098.004
T1112
T1140
T1189
T1190
T1192
T1204
T1204.001
T1204.002
T1210
T1218
T1218.005
T1500?
T1560
T1560.001
T1566
T1566.001
T1566.002
T1574
T1574.001
T1583
T1583.001
T1583.004
T1583.006
T1584
T1584.004
T1584.006
T1588
T1588.001
T1588.002
T1595
T1595.002
T1608
T1608.001
T1543
T1543.003
T1547
T1547.012
T1548
T1548.002

Software / Tooling

KTLVdoor
megacmd
Mimikatz
Cobalt Strike
CrimsonRAT
AndroRAT
BIOPASS RAT
Linux backdoor
Windows backdoor

Campaigns & Victims

Earth Lusca demonstrates a consistent multi‑stage operational pattern that begins with low‑friction initial access via spearphishing links or watering holes, followed by exploitation of public vulnerabilities (ZeroLogon, Exchange/Glassfish). The actor then establishes persistence through registry modifications and print‑processor DLL loading, leverages advanced credential‑dumping and privilege escalation tools such as Mimikatz DCSync, and propagates lateral movement using Cobalt Strike. Data staging occurs on compromised hosts before exfiltration via cloud services (MEGA) or remote services. Past campaigns have revealed activity in at least 2022–2024, targeting over fifty countries across industrial, government, and academic sectors. The group’s tempo appears steady but adaptive, often aligning with regional geopolitical events.

IOC Patterns

  • Suspicious registry key modification of HKLM\\SYSTEM\\ControlSet001\\Control\\Print\\Environments\\Windows x64\\Print Processors\\UDPrint to load spool.dll or a malicious DLL

Recommended Actions

  • Monitor and block domain registrations that imitate legitimate target domains used in watering‑hole attacks
  • Detect and block registry changes related to Print Processor entries for malware deployment
  • Patch Active Directory domain controllers against ZeroLogon (CVE‑2020‑1472)
  • Implement web filtering, URL reputation services, and drive‑by protection to detect malicious downloads
  • Track anomalous large uploads to cloud storage services such as MEGA from internal networks
  • Deploy endpoint detection that can identify Mimikatz, Cobalt Strike, and backdoor activity (KTLVdoor, CrimsonRAT, AndroRAT)
  • Conduct continuous user phishing awareness training
  • Enforce strict email filtering for malicious attachments or links
  • Monitor execution of KTLVdoor, CrimsonRAT, AndroRAT binaries via EDR/ATP tools
  • Block or quarantine IPs/domains linked to Earth Lusca infrastructure at the network level

Suggested Tags

Earth Lusca
TAG-22
China-based
APT
Cyber espionage
Watering Hole Attacks
ZeroLogon Exploit
Print Processor Loader
Credential Dumping
Spearphishing Link
Malicious File Injection
KTLVdoor Backdoor
CrimsonRAT
AndroRAT
Mimikatz
Cobalt Strike

Confidence Assessment

The core behavioral profile (watering holes, spearphishing links, ZeroLogon exploitation, use of KTLVdoor and Mimikatz) is corroborated by multiple independent vendor reports and MITRE ATT&CK mapping, providing a high confidence level for those tactics. Attribution to the Chinese state remains consistent with observed infrastructure reuse patterns, yet some IOC specifics (domain names, internal backends) are less complete due to limited open‑source data. Overall confidence in the attack model is medium‑high; gaps persist around full persistence mechanisms outside of KTLVdoor and cross‑platform capabilities.

ATT&CK Techniques

Discovery
8 techniques
Execution
11 techniques
Persistence
6 techniques
Resource Development
12 techniques
Stealth
9 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. TrendMicro EarthLusca 2022 — Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.
  2. Recorded Future TAG-22 July 2021 — INSIKT GROUP. (2021, July 8). Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling. Retrieved September 16, 2024.
  3. Recorded Future RedHotel August 2023 — Insikt Group. (2023, August 8). RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale. Retrieved March 11, 2024.
  4. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  5. www.eset.com — Cited by web research for: APT34
  6. attack.mitre.org — Cited by web research for: T1548
  7. attack.mitre.org — Cited by web research for: Akira
  8. apt.etda.or.th — Cited by web research for: Non Profit
  9. https://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.html — Cited by AI analysis.

Intel Summary

67

Techniques

54

Tools

2

Campaigns

17

IOCs

0

Observed Data

15

Tactics

Tags

APT
cyber espionage
espionage
Earth Lusca
TAG-22
China-based
Cyber espionage
Watering Hole Attacks
ZeroLogon Exploit
Print Processor Loader
Credential Dumping
Spearphishing Link
Malicious File Injection
KTLVdoor Backdoor
CrimsonRAT
AndroRAT
Mimikatz
Cobalt Strike

Details

MITRE ID
G1006
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
C
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--cc613a49-9bfa-4e22-98d1-15ffbb03f034
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.