Cyber Threat Report: 'Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections'

Report Author Trend Micro
Publication Date 2024-02-26
Original Reporting Source
Attributed to Nation China
Related Intrusion Sets Earth Lusca
Related Threat Actors i-SOON
Victim Sectors Non Profit, National Government, Education

Blog post from researchers at Trend Micro discussing Earth Lusca and potential links to Chinese contractor I-Soon. Earth Lusca is a China-linked threat actor active since at least 2020 with a history of changing its modus operandi. Recently, they launched a campaign leveraging Chinese-Taiwanese relations as a social engineering tactic to infect specific targets. This campaign, observed between December 2023 and January 2024, utilized a lure document discussing geopolitical issues. Recently leaked private documents connect Earth Lusca to a Chinese company called I-Soon, indicating a likely relationship between these groups.

Cyber Threat Graph Context

Explore how this report relates to the wider threat graph

Mitigations to defend against the techniques in this report

Identified MITRE ATT&CK Techniques

ATT&CK ID Title Associated Tactics
T1564.001 Hidden Files and Directories Defense Evasion
T1140 Deobfuscate/Decode Files or Information Defense Evasion
T1083 File and Directory Discovery Discovery
T1027.012 LNK Icon Smuggling Defense Evasion
T1001 Data Obfuscation Command and Control
T1027.009 Embedded Payloads Defense Evasion
T1059.003 Windows Command Shell Execution
T1204.001 Malicious Link Execution
T1041 Exfiltration Over C2 Channel Exfiltration
T1059.007 JavaScript Execution
T1204.002 Malicious File Execution
T1036.007 Double File Extension Defense Evasion
T1573 Encrypted Channel Command and Control
T1132 Data Encoding Command and Control
T1027.002 Software Packing Defense Evasion
T1202 Indirect Command Execution Defense Evasion
T1574.001 DLL Search Order Hijacking Defense Evasion, Persistence, Privilege Escalation
T1566.002 Spearphishing Link Initial Access