G1006: Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.CitationTrendMicro EarthLusca 2022
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.CitationTrendMicro EarthLusca 2022
Security context for executives and security teams
Earth Lusca matters because MITRE describes it as a suspected China-based espionage group with broad geographic and sector targeting, including government, media, education, telecommunications, cryptocurrency trading platforms, and COVID-19 research organizations. For leaders, the practical value is not the name itself but whether the organization can recognize the behaviors linked to the group: credential theft, Windows administrative utility abuse, discovery of systems and services, scheduled task persistence/execution, scripting, and use of dual-use or shared tooling such as Cobalt Strike, Mimikatz, PowerSploit, ShadowPad, and Winnti for Linux.
Executive priority
Prioritize this as a resilience and readiness issue for environments with Windows identity infrastructure, sensitive research or regulated data, telecommunications exposure, cryptocurrency operations, or operations in the countries and sectors listed by MITRE. Executives should ask whether SOC and incident response teams can prove visibility into credential-access behaviors such as LSASS access and DCSync, whether administrative tools are baselined well enough to separate normal operations from abuse, and whether audit evidence exists for identity hardening, endpoint logging, and incident containment decision-making.
Technical view
ATT&CK provides no official detection text for Earth Lusca, so defensive validation should be built from the related software and techniques. Focus on Windows identity and endpoint behaviors: Mimikatz and LSASS memory access, DCSync-like domain replication abuse, PowerShell and Visual Basic execution, WMI execution, scheduled task creation, process/service/user/network discovery, and use of native tools such as tasklist, certutil, and nltest. Also account for cross-platform and infrastructure discovery relationships where supplied, including Linux-related tooling such as Winnti for Linux and discovery techniques that include Linux, macOS, ESXi, network devices, and IaaS in their platform scope.
Likely telemetry
- Endpoint process creation and command-line telemetry for PowerShell, WMI, Visual Basic-related execution, certutil, tasklist, nltest, and scheduled task utilities
- Windows security events and identity telemetry relevant to LSASS access, privileged logons, domain controller activity, and directory replication-style behavior
- EDR or host telemetry for credential dumping tools, post-exploitation frameworks, suspicious module loads, memory access, and abnormal parent-child process chains
- Scheduled task creation, modification, and execution logs
- Service, process, user, network configuration, and network connection discovery logs from endpoints and servers
Detection direction
- Do not rely on group-name matching; validate detections against the related behaviors and tools supplied by ATT&CK.
- Baseline legitimate administrative use of tasklist, certutil, nltest, WMI, PowerShell, and scheduled tasks so detections can distinguish routine administration from unusual execution context, timing, destination, or privilege level.
- Prioritize high-fidelity detection around credential access: LSASS memory access, known credential dumping behavior, and DCSync-like activity from non-domain-controller or unexpected privileged principals.
- Correlate discovery behaviors: process, service, user, network configuration, network connection, and remote system discovery occurring in clusters after suspicious execution should raise priority.
- Tune for shared tooling carefully. Cobalt Strike, Mimikatz, PowerSploit, ShadowPad, and Winnti-related detections can overlap with testing, red-team activity, or other threat groups; require change tickets, approved testing windows, or asset context to reduce false positives.
Mitigation priorities
- Harden identity first: restrict and monitor privileged accounts, domain replication permissions, and administrative access to systems that can expose credentials.
- Reduce credential exposure on Windows endpoints and domain controllers through least privilege, administrative tiering, and protection of sensitive authentication material.
- Constrain and monitor powerful scripting and administration paths such as PowerShell, WMI, scheduled tasks, and certificate utilities without breaking approved operations.
- Improve endpoint and server logging before relying on analytics: process command lines, script activity, scheduled tasks, service changes, and identity events should be retained and searchable.
- Maintain tested incident response playbooks for credential theft scenarios, including domain controller review, privileged account reset decisions, and containment of systems showing discovery plus credential-access behavior.
Additional notes and limits
MITRE describes Earth Lusca as suspected China-based and notes overlap in malware commonly used by other Chinese threat groups while also citing researcher assessment that Earth Lusca techniques and infrastructure are separate. This makes attribution-sensitive handling important: use the group context to prioritize hypotheses, but base SOC escalation on observed behavior, affected assets, and confidence in telemetry.
The supplied ATT&CK object has no official detection text, no group-level tactics, and no group-level platforms. The practical guidance here is derived from the official description, aliases, external references, and listed relationships to software and techniques. Local asset exposure, logging quality, approved administrative activity, and incident evidence are required before concluding Earth Lusca-related activity.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.CitationTrendMicro EarthLusca 2022
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.CitationTrendMicro EarthLusca 2022
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
