Threat intelligence
- Suspected origin
- China
- Targeted countries
- China
- TLP
- WHITE
(Trend Micro) In this tech brief, we are going to expose a threat actor originating from China. Since the malware being used by the group, such as ShadowPad and Winnti, overlapped with other threat actors, its activities were attributed to other groups such as APT 41, Earth Baku, Sparkling Goblin, and the “Winnti” cluster in different reports. Our research reveals the different TTPs and the independent set of infrastructure that made us consider it a separate threat actor from the other known actors mentioned. Some reports named this threat actor “RedHotel, TAG-22” or “Fishmonger.” We decided to separate it from the Winnti umbrella and track this threat actor under the name “Earth Lusca.”
Our investigation of Earth Lusca started in mid-2021, when we discovered a campaign targeting customer service companies in China via a watering hole attack. Eventually, our monitoring and research lead to the publication of a blog post on a previously-unreported malware known as BIOPASS RAT. We continued monitoring the threat actor, eventually discovering a few more targeted operations against various targets worldwide. In this research, we will expose all of the groups TTPs and its current operations.
During our investigation, we also managed to reach some of the victims and gather interesting information from compromised servers that were used as watering holes. We were able to learn Earth Lusca’s reconnaissance and lateral movement techniques while working with our local incident response service team via our XDR system.
Also known as
Bronze UniversityCharcoal TyphoonChromiumControlXEarth LuscaG1006Red Dev 10Red ScyllaTAG-22
Vulnerabilities exploited
Tooling and malware
Cobalt StrikeShadowPadWinnti for LinuxcertutilMimikatzNBTscanNltestPowerSploitTasklist
MITRE ATT&CK techniques
T1090 ProxyT1112 Modify RegistryT1007 System Service DiscoveryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1049 System Network Connections DiscoveryT1057 Process DiscoveryT1482 Domain Trust DiscoveryT1047 Windows Management InstrumentationT1189 Drive-by CompromiseT1190 Exploit Public-Facing ApplicationT1210 Exploitation of Remote ServicesT1027 Obfuscated Files or InformationT1140 Deobfuscate/Decode Files or Information
Coverage 3
threat-intel
A new Windows variant of the SprySOCKS Linux backdoor, developed by the nation-state threat actor FishMonger (also known as Earth Lusca and Aquatic Panda), has been discovered targeting government organizations in Hondur…

threat-intel
Researchers have identified new Windows variants of the SprySOCKS backdoor, initially linked to the Chinese state-sponsored threat actor Earth Lusca (also known as Aquatic Panda). These variants, designated WIN_DRV and W…

threat-intel
Windows variants of the SprySOCKS Linux malware, previously linked to the Earth Lusca threat actor, have been used to target government organizations in Taiwan, Thailand, Pakistan, and Honduras. These variants offer adva…