G1006: Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[1]
Security context for executives and security teams
G1006: Earth Lusca describes [Earth Lusca](https://attack.mitre.org/groups/G1006) is a suspected China-based cyber espionage group that has been active since at least April 2019. [Earth Lusca](https://attack.mitre.org/groups/G1006) has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 resea...
Executive priority
G1006: Earth Lusca is an official MITRE ATT&CK group. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.
Technical view
Security teams should validate G1006: Earth Lusca by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.
Likely telemetry
- Official ATT&CK relationships and object metadata
Detection direction
- Validate whether G1006: Earth Lusca appears in your detection coverage and tabletop scenarios.
- Use the object to align executive risk language with SOC, incident response, and detection engineering work.
- Do not treat ATT&CK relationship context as attribution without corroborating evidence.
Mitigation priorities
- Map the object to existing controls and identify missing telemetry or response ownership.
- Prioritize mitigations that reduce exposure on the listed platforms and tactics.
- Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits
Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.
This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[1]
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
Techniques used
This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.
| Domain | ID | Name | Relationship / procedure |
|---|---|---|---|
| Enterprise | T1583.006 | Web ServicesSub-technique | Earth Lusca has established GitHub accounts to host their malware.[1] |
| Enterprise | T1027.003 | SteganographySub-technique | Earth Lusca has used steganography to hide shellcode in a BMP image file.[1] |
| Enterprise | T1608.001 | Upload MalwareSub-technique | Earth Lusca has staged malware and malicious files on compromised web servers, GitHub, and Google Drive.[1] |
| Enterprise | T1098.004 | SSH Authorized KeysSub-technique | Earth Lusca has dropped an SSH-authorized key in the `/root/.ssh` folder in order to access a compromised server with SSH.[1] |
| Enterprise | T1059.005 | Visual BasicSub-technique | Earth Lusca used VBA scripts.[1] |
| Enterprise | T1189 | Drive-by Compromise | Earth Lusca has performed watering hole attacks.[1] |
| Enterprise | T1018 | Remote System Discovery | Earth Lusca used the command |
| Enterprise | T1584.006 | Web ServicesSub-technique | Earth Lusca has compromised Google Drive repositories.[1] |
| Enterprise | T1059.007 | JavaScriptSub-technique | Earth Lusca has manipulated legitimate websites to inject malicious JavaScript code as part of their watering hole operations.[1] |
| Enterprise | T1036.005 | Match Legitimate Resource Name or LocationSub-technique | Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.[1] |
| Enterprise | T1140 | Deobfuscate/Decode Files or Information | Earth Lusca has used certutil to decode a string into a cabinet file.[1] |
| Enterprise | T1583.001 | DomainsSub-technique | Earth Lusca has registered domains, intended to look like legitimate target domains, that have been used in watering hole attacks.[1] |
| Enterprise | T1033 | System Owner/User Discovery | Earth Lusca collected information on user accounts via the |
| Enterprise | T1547.012 | Print ProcessorsSub-technique | Earth Lusca has added the Registry key `HKLM\SYSTEM\ControlSet001\Control\Print\Environments\Windows x64\Print Processors\UDPrint” /v Driver /d “spool.dll /f` to load malware as a Print Processor.[1] |
| Enterprise | T1059.001 | PowerShellSub-technique | Earth Lusca has used PowerShell to execute commands.[1] |
| Enterprise | T1059.006 | PythonSub-technique | Earth Lusca used Python scripts for port scanning or building reverse shells.[1] |
| Enterprise | T1057 | Process Discovery | Earth Lusca has used Tasklist to obtain information from a compromised host.[1] |
| Enterprise | T1053.005 | Scheduled TaskSub-technique | Earth Lusca used the command |
| Enterprise | T1574.001 | DLLSub-technique | Earth Lusca has placed a malicious payload in `%WINDIR%\SYSTEM32\oci.dll` so it would be sideloaded by the MSDTC service.[1] |
| Enterprise | T1112 | Modify Registry | Earth Lusca modified the registry using the command |
| Enterprise | T1047 | Windows Management Instrumentation | Earth Lusca used a VBA script to execute WMI.[1] |
| Enterprise | T1003.001 | LSASS MemorySub-technique | Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.[1] |
| Enterprise | T1218.005 | MshtaSub-technique | Earth Lusca has used `mshta.exe` to load an HTA script within a malicious .LNK file.[1] |
| Enterprise | T1482 | Domain Trust Discovery | Earth Lusca has used Nltest to obtain information about domain controllers.[1] |
| Enterprise | T1567.002 | Exfiltration to Cloud StorageSub-technique | Earth Lusca has used the megacmd tool to upload stolen files from a victim network to MEGA.[1] |
| Enterprise | T1548.002 | Bypass User Account ControlSub-technique | Earth Lusca has used the Fodhelper UAC bypass technique to gain elevated privileges.[1] |
| Enterprise | T1588.002 | ToolSub-technique | Earth Lusca has acquired and used a variety of open source tools.[1] |
| Enterprise | T1007 | System Service Discovery | Earth Lusca has used Tasklist to obtain information from a compromised host.[1] |
| Enterprise | T1204.002 | Malicious FileSub-technique | Earth Lusca required users to click on a malicious file for the loader to activate.[1] |
| Enterprise | T1190 | Exploit Public-Facing Application | Earth Lusca has compromised victims by directly exploiting vulnerabilities of public-facing servers, including those associated with Microsoft Exchange and Oracle GlassFish.[1] |
| Enterprise | T1090 | Proxy | Earth Lusca adopted Cloudflare as a proxy for compromised servers.[1] |
| Enterprise | T1027 | Obfuscated Files or Information | Earth Lusca used Base64 to encode strings.[1] |
| Enterprise | T1543.003 | Windows ServiceSub-technique | Earth Lusca created a service using the command |
| Enterprise | T1566.002 | Spearphishing LinkSub-technique | Earth Lusca has sent spearphishing emails to potential targets that contained a malicious link.[1] |
| Enterprise | T1560.001 | Archive via UtilitySub-technique | Earth Lusca has used WinRAR to compress stolen files into an archive prior to exfiltration.[1] |
| Enterprise | T1583.004 | ServerSub-technique | Earth Lusca has acquired multiple servers for some of their operations, using each server for a different role.[1] |
| Enterprise | T1049 | System Network Connections Discovery | Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” (Event ID 1024) to obtain network information from RDP connections. Earth Lusca has also used netstat from a compromised system to obtain network connection information.[1] |
| Enterprise | T1595.002 | Vulnerability ScanningSub-technique | Earth Lusca has scanned for vulnerabilities in the public-facing servers of their targets.[1] |
| Enterprise | T1016 | System Network Configuration Discovery | Earth Lusca used the command |
| Enterprise | T1588.001 | MalwareSub-technique | Earth Lusca has acquired and used a variety of malware, including Cobalt Strike.[1] |
| Enterprise | T1584.004 | ServerSub-technique | Earth Lusca has used compromised web servers as part of their operational infrastructure.[1] |
| Enterprise | T1204.001 | Malicious LinkSub-technique | Earth Lusca has sent spearphishing emails that required the user to click on a malicious link and subsequently open a decoy document with a malicious loader.[1] |
| Enterprise | T1210 | Exploitation of Remote Services | Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).[1] |
| Enterprise | T1003.006 | DCSyncSub-technique | Earth Lusca has used a |
Groups, software, and campaigns
S0002: Mimikatz
S0194: PowerSploit
PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration. [1] [2] [3]
S0057: Tasklist
S0160: certutil
S0154: Cobalt Strike
Cobalt Strike is a commercial, full-featured, remote access tool that bills itself as “adversary simulation software designed to execute targeted attacks and emulate the post-exploitation actions of advanced threat actors”. Cobalt Strike’s interactive post-exploit capabilities cover the full range of ATT&CK tactics, all executed within a single, integrated system.[1]
In addition to its own capabilities, Cobalt Strike leverages the capabilities of other well-known tools such as Metasploit and Mimikatz.[1]
S0430: Winnti for Linux
Winnti for Linux is a trojan, seen since at least 2015, designed specifically for targeting Linux systems. Reporting indicates the winnti malware family is shared across a number of actors including Winnti Group. The Windows variant is tracked separately under Winnti for Windows.[1]
S0359: Nltest
S0590: NBTscan
S0596: ShadowPad
All related ATT&CK context
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Imported snapshots across ATT&CK releases(2)
| Release | Bundle imported | Object version | Modified | Status | Raw hash |
|---|---|---|---|---|---|
| 19.2 | 2.1 | Current bundle | ddcf0d22795f… | ||
| 19.1 | 2.1 | Older bundle | 7e211d515960… |
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
External references and citations
MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.
- [1]TrendMicro EarthLusca 2022
Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.
Open source URL - [2]CHROMIUM
(Citation: Microsoft Threat Actor Naming July 2023) (Citation: Recorded Future RedHotel August 2023)
- [3]Charcoal Typhoon
(Citation: Microsoft Threat Actor Naming July 2023)
- [4]ControlX
(Citation: Microsoft Threat Actor Naming July 2023)
- [5]Microsoft Threat Actor Naming July 2023
Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
Open source URL - [6]Recorded Future RedHotel August 2023
Insikt Group. (2023, August 8). RedHotel: A Prolific, Chinese State-Sponsored Group Operating at a Global Scale. Retrieved March 11, 2024.
Open source URL - [7]Recorded Future TAG-22 July 2021
INSIKT GROUP. (2021, July 8). Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling. Retrieved September 16, 2024.
Open source URL - [8]TAG-22
(Citation: Recorded Future TAG-22 July 2021)
- [9]mitre-attackG1006Open source URL
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
