Earth Lusca

Actor Type Commercial Provider
Attributed to Nation China
Directly Linked Intrusion Sets RedHotel , TAG-22
Associated Threat Actor i-SOON

Earth Lusca is an intrusion set which has been observed by Trend Micro since 2021. The group use spear phishing and watering holes to gain initial access to targets and have been observed using the Winnti malware.

The groups targets include government, pro-democracy and human rights organizations in Hong Cong, educational institutions and more, primarily for espionage purposes.

Trend Micro also report instances of the group conducting financially motivated attacks against gambling and cryptocurrency companies.

Cyber Threat Graph Context

Explore how this Intrusion Set relates to the wider threat graph

Earth Lusca Threat Reports

Report

Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections

Blog post from researchers at Trend Micro discussing Earth Lusca and potential links to Chinese contractor I-Soon. Earth Lusca is a China-linked ...

References

MITRE ATT&CK Techniques

MITRE ATT&CK techniques observed in use by this intrusion set.