ATT&CKGroupsEarth Lusca

Earth Lusca

G1006

Threat group.View on attack.mitre.org

About this group

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.

Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.

Techniques used44

Procedure examples44

TechniqueProcedure example
T1003.001
LSASS Memory

Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.

T1003.006
DCSync

Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.

T1007
System Service Discovery

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1016
System Network Configuration Discovery

Earth Lusca used the command ipconfig to obtain information about network configurations.

T1018
Remote System Discovery

Earth Lusca used the command powershell “Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list -
property * | findstr “Address””
to find the network information of successfully logged-in accounts to discovery addresses of other machines. Earth Lusca has also used multiple scanning tools to discover other machines within the same compromised network.

T1027
Obfuscated Files or Information

Earth Lusca used Base64 to encode strings.

T1027.003
Steganography

Earth Lusca has used steganography to hide shellcode in a BMP image file.

T1033
System Owner/User Discovery

Earth Lusca collected information on user accounts via the whoami command.

T1036.005
Match Legitimate Resource Name or Location

Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service.

T1047
Windows Management Instrumentation

Earth Lusca used a VBA script to execute WMI.

T1049
System Network Connections Discovery

Earth Lusca employed a PowerShell script called RDPConnectionParser to read and filter the Windows event log “Microsoft-Windows-TerminalServices-RDPClient/Operational”
(Event ID 1024) to obtain network information from RDP connections. Earth Lusca has also used netstat from a compromised system to obtain network connection information.

T1053.005
Scheduled Task

Earth Lusca used the command schtasks /Create /SC ONLOgon /TN WindowsUpdateCheck /TR “[file path]” /ru system for persistence.

T1057
Process Discovery

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1059.001
PowerShell

Earth Lusca has used PowerShell to execute commands.

T1059.005
Visual Basic

Earth Lusca used VBA scripts.

View all 44 procedure examples

Software9

Campaigns0

None recorded.

References1

  1. TrendMicro EarthLusca 2022 Open source
    Chen, J., et al. (2022). Delving Deep: An Analysis of Earth Lusca’s Operations. Retrieved July 1, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.