Cyber Threat Report: 'Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections'

Report Author Trend Micro
Publication Date 2024-02-26
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets Earth Lusca
Related Threat Actors i-SOON
Victim Sectors National Government, Education, Non Profit

Blog post from researchers at Trend Micro discussing Earth Lusca and potential links to Chinese contractor I-Soon. Earth Lusca is a China-linked threat actor active since at least 2020 with a history of changing its modus operandi. Recently, they launched a campaign leveraging Chinese-Taiwanese relations as a social engineering tactic to infect specific targets. This campaign, observed between December 2023 and January 2024, utilized a lure document discussing geopolitical issues. Recently leaked private documents connect Earth Lusca to a Chinese company called I-Soon, indicating a likely relationship between these groups.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques