Home/Threat Actor/Earth Lusca
Threat Actor

Earth Lusca

earth_lusca · china · active since 2019

Earth Lusca (Aquatic Panda / Charcoal Typhoon / Bronze University / TAG-22 / G1006) is a China-aligned cyber-espionage cluster active since 2019, widely assessed to operate with MSS tasking and operationally adjacent to the broader Winnti / APT41 ecosystem of China-aligned dual-motivation actors, defined by its parallel espionage and financially-motivated operational streams against Taiwanese, Hong Kong, Tibetan, Uyghur, Falun Gong, Catholic-Church- of-Hong-Kong, Vietnamese, Philippine, US, and UK targets alongside gambling, online-gaming, and cryptocurrency-exchange targets, and by a toolkit anchored on ShadowPad, Winnti malware family, PlugX, Doraemon and FunnySwitch backdoors, Cobalt Strike Beacon, and BadIIS web-shell deployment for long-dwell persistence.

china confidence: high 16 aliases MITRE ATT&CK G0143 ↗

Profile

Earth Lusca (also tracked as Aquatic Panda, Charcoal Typhoon [Microsoft], Chromium, Bronze University [Secureworks], TAG-22 [Recorded Future], and MITRE ATT&CK G1006) is a China-aligned cyber-espionage cluster active since at least mid-2019 and publicly disclosed in consolidated form by Trend Micro in January 2022 ("Delving Deep, An Analysis of Earth Lusca's Operations"). The cluster is widely assessed by vendor research to operate in alignment with Chinese state interests, likely with MSS (Ministry of State Security) tasking, and is treated as operationally adjacent to but distinct from the broader Winnti / APT41 ecosystem of China-aligned dual-motivation actors. No formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published.

the "MSS-aligned" framing is the dominant vendor assessment but is suspected rather than formally confirmed. A defining feature of Earth Lusca, and the feature that most clearly aligns the cluster with the broader Winnti / APT41 pattern, is its dual espionage-and-financial-motivation operational pattern. Geopolitical espionage targeting (Taiwanese and Hong Kong democracy-movement entities, Tibetan and Uyghur diaspora organizations, the Catholic Church of Hong Kong, Falun Gong, Vietnamese and Philippine government, US and UK think tanks researching China policy, Mongolian and Cambodian government) runs in parallel with financially-motivated operations against gambling, online-gaming, and cryptocurrency exchange targets, with shared infrastructure and tooling across both motivation streams. The dual-motivation pattern raises ongoing analytic questions about whether the financial operations represent sanctioned MSS moonlighting (the APT41 precedent) or a separate funding stream. Operationally Earth Lusca operates a comparatively standard China-aligned toolkit with substantial Winnti-ecosystem overlap. Core implants include ShadowPad (the modular Winnti-shared implant), Winnti malware family components, PlugX / Korplug, Doraemon backdoor, and FunnySwitch backdoor, with heavy reliance on Cobalt Strike Beacon for hands-on-keyboard operations. Recent campaigns have added BadIIS web-shell deployment for long-dwell persistence in compromised IIS-hosted web environments, with SEO-fraud and traffic-redirection components providing direct monetization alongside espionage objectives. Initial access is varied: exploitation of public-facing vulnerabilities (the cluster has been active against Log4Shell CVE-2021-44228, Citrix CVE-2019-19781, Exchange ProxyLogon and ProxyShell, Microsoft Office Follina CVE-2022-30190, and others), spear-phishing with weaponized Office documents, supply-chain compromise of regional software vendors, and watering-hole compromises of websites associated with target communities. A handful of operational notes: First, Earth Lusca is operationally distinct from APT41 / Wicked Panda (already covered in apt41_wickedpanda.yaml under MSS / Chengdu 404 framing), from Winnti Group (a broader umbrella with tooling-overlap rather than operational identity), and from RedHotel (an adjacent / overlapping cluster tracked separately by Recorded Future and pending its own record in this corpus). The ShadowPad and Winnti malware family tooling overlap among these clusters complicates attribution at the malware-family level but cluster-level operational signatures remain distinguishable. Second, the Microsoft "Charcoal Typhoon" naming places Earth Lusca in the Typhoon taxonomy alongside Volt, Flax, Salt, Silk, and Granite Typhoons (Volt, Flax, Salt, and Silk are already covered separately in this corpus.

Granite Typhoon is the Microsoft naming for Gallium, also covered). Third, the cluster's MSS-alignment framing, though dominant in vendor reporting, has not been confirmed by formal state attribution and should be presented as suspected.

Aliases

16
earth luscaearth_luscaearthluscaaquatic pandaaquatic_pandaaquaticpandacharcoal typhooncharcoal_typhoonchromiumbronze universitybronze_universitytag-22tag_22atk 240atk240g1006

Notable Campaigns

8
2024-2025BadIIS Web-Shell Campaigns and Continued Operations (2024-2025)
2023Microsoft Charcoal Typhoon Renaming and Continued Tracking (2023)
2022-2024Sustained Cobalt Strike and ShadowPad Operations (2022-2024)
2022Trend Micro: Delving Deep, An Analysis of Earth Lusca's Operations (January 2022)
2021-2024Financially-Motivated Operations Adjacent to Espionage (2021-2024)
2021-2023Religious-Organization and Dissident-Community Targeting (2021-2023)
2021Recorded Future TAG-22 Tracking (2021)
2019Earliest Documented Activity (2019)

Attribution & Reporting

Attributed by
Trend MicroMicrosoftRecorded Future Insikt GroupCrowdStrikeSecureworksMandiantCisco TalosKasperskySentinelOneESETVolexitySymantecSophosGroup-IBCluster25CyfirmaQiAnXin RedDrip360 Threat Intelligence Center
Key reporting
reportTrend Micro: Delving Deep, An Analysis of Earth Lusca's Operations (January 2022), seminal 138-page report
reportTrend Micro: Earth Lusca Targets High-Value Targets in Both Public and Private Sectors (January 2022)
reportRecorded Future Insikt Group: TAG-22, China-Linked Threat Actor Tracking (2021)
reportRecorded Future Insikt Group: RedHotel, A China-Linked Threat Actor (August 2023), adjacent / overlapping cluster
reportCrowdStrike: Aquatic Panda, Log4j Exploitation Against Academic Institution (December 2021)
reportSecureworks: Bronze University Threat Profile
reportMicrosoft: Shift to a New Threat Actor Naming Taxonomy, Charcoal Typhoon (April 2023)
reportSentinelOne Labs: BadIIS, China-Linked SEO Manipulation and Backdoor Campaigns (2024)
reportSekoia: Active China-Aligned Clusters (multiple, 2023-2024)
reportMandiant: ShadowPad, Modular Backdoor Used Across the Winnti Ecosystem
reportCisco Talos: ShadowPad Across Multiple Chinese-Aligned Clusters
reportGroup-IB: Earth Lusca Tracking (2022-2024)
reportCluster25: Earth Lusca Operational Profile (2022-2024)
reportCyfirma: Earth Lusca Strikes Asian Targets (multiple years)
reportMalpedia Actor Profile: Earth Lusca
reportMITRE ATT&CK Group G1006, Earth Lusca

Operational

State sponsor

Suspected China-aligned advanced persistent threat group, widely assessed by vendor research (Trend Micro, Microsoft, Recorded Future, CrowdStrike, Secureworks) to operate in alignment with Chinese state interests, likely with MSS (Ministry of State Security) tasking, and operationally adjacent to the broader Winnti / APT41 ecosystem of China-aligned dual-motivation actors. Earth Lusca is widely treated as a distinct operational cluster rather than as an alias for Winnti or APT41, Trend Micro's January 2022 seminal disclosure "Delving Deep, An Analysis of Earth Lusca's Operations" characterized the cluster as operating independently while sharing tooling (notably ShadowPad and Winnti malware family components) with the broader Winnti ecosystem. The cluster's combination of geopolitical espionage targeting (Tibetan, Uyghur, Falun Gong, Taiwanese, Hong Kong, Vietnamese, Philippine, and US/UK targets) with parallel financially-motivated operations (gambling, cryptocurrency, online-gaming) is one of the cluster's defining features and mirrors the dual-motivation pattern seen in APT41 / Wicked Panda and other Winnti-cluster actors.

No formal US, UK, or EU government attribution to a specific PRC ministry or unit has been published.

Motivations
espionage, intelligence_gathering, geopolitical_collection, dissident_surveillance, religious_organization_surveillance, financial_gain, cryptocurrency_theft, gambling_targeting
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)57/60 · 95%
Analytics (MITRE CAR)31/60 · 51%
Runtime / container (Falco)6/60 · 10%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)16/60 · 26%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

3 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
MSHTASCANLINESHARPHOUNDSMBEXECSNEAKYDOOR
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin