Earth Lusca is a China-based threat actor conducting politically motivated espionage and financially driven cyber operations.
Analyst brief
Earth Lusca is a China-based threat actor conducting both politically motivated espionage and financially driven cyber operations. It primarily targets government institutions, telecommunications, education, media, cryptocurrency sectors, as well as religious and pro-democracy organizations of interest to the Chinese government. Key TTPs include initial access via vulnerability scanning (T1595.002) and drive-by compromise (T1189), leveraging Cobalt Strike, Mimikatz, ShadowPad, and Winnti for Linux for lateral movement and credential access, with data exfiltration to cloud storage (T1567.002). Defenders should prioritize patching public-facing servers, monitoring for Cobalt Strike C2 traffic and anomalous authentication attempts.
Earth Lusca
CHROMIUMControlXTAG-22
activeunknown
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication companies, religious organizations, and other civil society groups. Earth Lusca's tools closely resemble those used by Winnti Umbrella, but the group appears to operate separately from Winnti. Earth Lusca has also been observed targeting cryptocurrency payment platforms and cryptocurrency exchanges in what are likely financially motivated attacks.
origin (suspected)
🇨🇳China
target countries (as stated by the source)
AustraliaChinaFranceGermany
target sectors
Gambling companiesGovernment InstitutionsEducationMedia and Entertainment
Monitor registry changes to detect Modify Registry technique.
FAQ2
What are the main tools used by Earth Lusca?+
Earth Lusca primarily uses Cobalt Strike, Mimikatz, ShadowPad, and Winnti for Linux.
Which sectors does Earth Lusca target?+
They primarily target government institutions, telecommunications, education, media, cryptocurrency sectors, as well as religious and human rights organizations.