Earth Lusca

Threat Actor updated a month ago (2024-09-05T18:18:23.486Z)
Download STIX
Preview STIX
Earth Lusca, a threat actor identified as being Chinese-speaking, has been active since at least the first half of 2023. The group primarily targets organizations in Southeast Asia, Central Asia, and the Balkans. Recently, it has expanded its arsenal with SprySOCKS Linux malware, a new addition that poses a significant threat to cybersecurity. This move was reported by security affairs, highlighting the increasing sophistication and adaptability of Earth Lusca's operations. The group has also been linked with high confidence to the usage of KTLVdoor, a multiplatform backdoor malware. This was discovered by Trend Micro researchers who noted an attack against a trading company in China where this new backdoor was used. However, several other samples of this malware family could not be definitively tied to Earth Lusca, indicating potential operational diversity or collaboration with other threat actors. The size of the infrastructure that has been discovered associated with Earth Lusca is unusually large, further underscoring the scale and potential impact of their activities. Despite these findings, it remains unclear how Earth Lusca distributes the new backdoor KTLVdoor. This lack of clarity presents a challenge for cybersecurity efforts, as understanding distribution methods is crucial for effective prevention and response strategies. As such, further investigation into Earth Lusca's tactics and techniques is necessary to mitigate future threats. The reports have provided Indicators of Compromise (IoCs) which can aid in detection and prevention of these threats.
Description last updated: 2024-09-05T18:15:31.903Z
What's your take? (Question 1 of 5)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at. Create a free account to see the source evidence for each alias, and help fix any errors.
Alias DescriptionVotes
I-Soon is a possible alias for Earth Lusca. i-Soon, also known as Anxun, is a threat actor identified as a private industry contractor for the Chinese Ministry of Public Security (MPS). The company has recently been implicated in a massive data leak that surfaced on Github. As elaborated by Tom Uren and Catalin Cimpanu, i-Soon frequently init
4
Earth Krahang is a possible alias for Earth Lusca. Earth Krahang is a threat actor, a term used in cybersecurity to describe an entity responsible for malicious activities. This could be an individual, a private company, or even a government organization. In the world of cybersecurity, unique names are often given to these actors to differentiate th
3
Winnti is a possible alias for Earth Lusca. Winnti, a notorious threat actor group, has been linked to several sophisticated cyber-espionage activities. First identified by Kaspersky in 2013, it is believed that the group has been active since at least 2007, primarily targeting software supply chains to spread malware. Winnti is part of the A
3
Bronze University is a possible alias for Earth Lusca. Bronze University, also known as Aquatic Panda, ControlX, RedHotel, and Earth Lusca, is a threat actor group believed to be a Chinese state-sponsored hacking operation. The group has been active since 2021, targeting government, aerospace, education, telecommunications, media, and research organizat
2
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Malware
Backdoor
Lateral Move...
Linux
Espionage
Web Shell
Exploit
Chinese
Windows
Loader
Vulnerability
Remote Code ...
Apt
Github
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Malware
To see the evidence that has resulted in these malware associations, create a free account
Alias DescriptionAssociation TypeVotes
The Sprysocks Malware is associated with Earth Lusca. SprySOCKS is a new strain of malware that has recently been added to the arsenal of Earth Lusca, an advanced persistent threat (APT) group known for its sophisticated cyberattacks. Malware, short for malicious software, is designed to exploit and damage computers or devices without the user's knowleUnspecified
6
The ShadowPad Malware is associated with Earth Lusca. ShadowPad is a modular malware that has been utilized by various Chinese threat actors since at least 2017. It's a malicious software designed to infiltrate computer systems, often without the user's knowledge, and can cause significant damage by stealing personal information, disrupting operations,Unspecified
2
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
Alias DescriptionAssociation TypeVotes
The Earth Akhlut Threat Actor is associated with Earth Lusca. Earth Akhlut is a recognized threat actor, originating from China, known for its malicious activities in the realm of cybersecurity. Since 2019, it has been involved in distributing the Shadowpad malware, a sophisticated tool that has caused significant concern within the cybersecurity community. ThUnspecified
3
Associated Vulnerabilities
To see the evidence that has resulted in these vulnerability associations, create a free account
Alias DescriptionAssociation TypeVotes
The CVE-2022-40684 Vulnerability is associated with Earth Lusca. CVE-2022-40684 is a significant software vulnerability identified in Fortinet devices, specifically relating to an authentication bypass flaw. This flaw in the software design or implementation allows threat actors to exploit the vulnerability, compromising network security and providing unauthorizeUnspecified
2
The CVE-2022-39952 Vulnerability is associated with Earth Lusca. CVE-2022-39952 is a critical vulnerability in Fortinet's network access control suite, FortiNAC. This flaw, which resides in the software design or implementation, could lead to arbitrary code execution, posing a severe threat to network security. The vulnerability was identified and addressed by FoUnspecified
2
The CVE-2019-18935 Vulnerability is associated with Earth Lusca. CVE-2019-18935 is a .NET deserialization vulnerability in the Progress Telerik user interface (UI) for ASP.NET AJAX, located in Microsoft's Internet Information Services (IIS) web server. This flaw in software design or implementation was exploited by multiple cyber threat actors, including an AdvanUnspecified
2
Source Document References
Information about the Earth Lusca Threat Actor was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
DARKReading
a month ago
Securityaffairs
a month ago
Securityaffairs
2 months ago
Securityaffairs
2 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
3 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
4 months ago
Securityaffairs
5 months ago
Securityaffairs
5 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
Securityaffairs
6 months ago
BankInfoSecurity
7 months ago