Earth Lusca
Also reported as TAG-22, Charcoal Typhoon, CHROMIUM and ControlX.
Reports per quarter
Techniques seen in the last two years
- T1059.001 2 reports in ATT&CK
- T1059.003 2 reports reports only
- T1140 2 reports in ATT&CK
- T1566.002 2 reports in ATT&CK
- T1583.001 2 reports in ATT&CK
- T1583.004 2 reports in ATT&CK
- T1001 1 report reports only
- T1003.001 1 report in ATT&CK
- T1003.002 1 report reports only
- T1007 1 report in ATT&CK
Show all 46 techniques Show fewer
- T1012 1 report reports only
- T1016 1 report in ATT&CK
- T1021.002 1 report reports only
- T1027.002 1 report reports only
- T1027.009 1 report reports only
- T1027.012 1 report reports only
- T1036.007 1 report reports only
- T1041 1 report reports only
- T1055.012 1 report reports only
- T1057 1 report in ATT&CK
- T1059.007 1 report in ATT&CK
- T1071 1 report reports only
- T1071.001 1 report reports only
- T1072 1 report reports only
- T1082 1 report reports only
- T1083 1 report reports only
- T1087.001 1 report reports only
- T1095 1 report reports only
- T1105 1 report reports only
- T1112 1 report in ATT&CK
- T1132 1 report reports only
- T1202 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.002 1 report in ATT&CK
- T1543.003 1 report in ATT&CK
- T1555.003 1 report reports only
- T1556.002 1 report reports only
- T1564.001 1 report reports only
- T1573 1 report reports only
- T1573.001 1 report reports only
- T1573.002 1 report reports only
- T1574 1 report reports only
- T1574.001 1 report in ATT&CK
- T1583.003 1 report reports only
- T1583.008 1 report reports only
- T1584.004 1 report in ATT&CK
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2008-3431 KEV
- CVE-2012-5469
- CVE-2012-5687
- CVE-2013-5947
- CVE-2014-0160 KEV
- CVE-2014-0346
- CVE-2014-1225
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-8361 KEV
- CVE-2014-9583
- CVE-2015-0554
Show all 103 CVEs Show fewer
- CVE-2015-2051 KEV
- CVE-2015-7248
- CVE-2015-7254
- CVE-2016-5195 KEV
- CVE-2017-0144 KEV ransomware
- CVE-2017-0199 KEV ransomware
- CVE-2017-0213 KEV ransomware
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-8570 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10561 KEV
- CVE-2018-13379 KEV ransomware
- CVE-2018-8872
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-16098
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-9489
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10826
- CVE-2020-10827
- CVE-2020-13756
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-14882 KEV
- CVE-2020-15782
- CVE-2020-16040
- CVE-2020-2021 KEV ransomware
- CVE-2020-8468 KEV
- CVE-2021-1675 KEV ransomware
- CVE-2021-1879 KEV
- CVE-2021-21166 KEV
- CVE-2021-22205 KEV ransomware
- CVE-2021-22555 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26855 KEV ransomware
- CVE-2021-26868
- CVE-2021-30551 KEV
- CVE-2021-31207 KEV ransomware
- CVE-2021-33742 KEV
- CVE-2021-34473 KEV ransomware
- CVE-2021-34481
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-36958
- CVE-2021-4034 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-43936
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-1040 KEV
- CVE-2022-24086 KEV
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-39952
- CVE-2022-40684 KEV ransomware
- CVE-2022-41040 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2023-46747 KEV ransomware
- CVE-2024-1709 KEV ransomware
- CVE-2024-24919 KEV ransomware
- CVE-2024-28000
- CVE-2024-30051 KEV ransomware
- CVE-2024-32896 KEV
- CVE-2024-43451 KEV
- CVE-2024-44000
- CVE-2024-45195 KEV
- CVE-2024-8190 KEV
- CVE-2024-8963 KEV
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor ShadowPad (Malware Family)
-
Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Earth Lusca - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor PlugX (Malware Family)
Show all 161 reports Show fewer
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor NjRAT (Malware Family)
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections | Trend Micro (US)
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections | Trend Micro (US)
-
Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Staying ahead of threat actors in the age of AI _ Microsoft Security Blog
-
PwC Cyber Threats 2022: A Year in Retrospect.pdf
The original link failed its last check. Original publisher Detailsfor PwC Cyber Threats 2022: A Year in Retrospect.pdf
-
Delving Deep: An Analysis of Earth Lusca's Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Delving Deep: An Analysis of Earth Lusca's Operations
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Winnti is Coming - Evolution after Prosecution
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Chinese State-Sponsored Activity Group TAG-22 Targets Nepal, the Philippines, and Taiwan Using Winnti and Other Tooling
-
The original link failed its last check. Original publisher Detailsfor Презентация PowerPoint
-
InSideCopy: How this APT continues to evolve its arsenal
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor InSideCopy: How this APT continues to evolve its arsenal
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Intezer-2020-Go-Malware-Round-Up.pdf
The original link failed its last check. Original publisher Detailsfor Intezer-2020-Go-Malware-Round-Up.pdf
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
China cyber attacks- the current threat landscape
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor China cyber attacks- the current threat landscape
-
The original link failed its last check. Original publisher Detailsfor winnti-2020-rus.pdf
-
2020-q2-spamhaus-botnet-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor 2020-q2-spamhaus-botnet-threat-report.pdf
-
AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
The original link failed its last check. Original publisher Detailsfor AutoIt-Compiled Worm Sends Fileless BLADABINDI/njRAT
Newest first. Details opens the report in Explore.