Threat group.View on attack.mitre.org
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process. |
| T1003.006 DCSync |
Earth Lusca has used a |
| T1007 System Service Discovery |
Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1016 System Network Configuration Discovery |
Earth Lusca used the command |
| T1018 Remote System Discovery |
Earth Lusca used the command |
| T1027 Obfuscated Files or Information |
Earth Lusca used Base64 to encode strings. |
| T1027.003 Steganography |
Earth Lusca has used steganography to hide shellcode in a BMP image file. |
| T1033 System Owner/User Discovery |
Earth Lusca collected information on user accounts via the |
| T1036.005 Match Legitimate Resource Name or Location |
Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service. |
| T1047 Windows Management Instrumentation |
Earth Lusca used a VBA script to execute WMI. |
| T1049 System Network Connections Discovery |
Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational” |
| T1053.005 Scheduled Task |
Earth Lusca used the command |
| T1057 Process Discovery |
Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1059.001 PowerShell |
Earth Lusca has used PowerShell to execute commands. |
| T1059.005 Visual Basic |
Earth Lusca used VBA scripts. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.