Earth Lusca — what to detect, and what we don’t know.

UAE targets inside a wide Chinese espionage and for-profit remit.

44 techniques 14 detection behaviours 9 tools mapped United Arab Emirates

Also tracked as  CHROMIUM · ControlX · TAG-22 · FISHMONGER · BRONZE UNIVERSITY · AQUATIC PANDA · Red Dev 10 · RedHotel · Charcoal Typhoon · BountyGlad · Red Scylla · Aquatic Panda

Attributed to
CN State-sponsored, I-Soon
Gulf victimology
1 United Arab Emirates
Techniques
44 across 14 tactics
Tooling
9 0 actor-specific · 9 commodity
Reporting
13 6 outlets · 18 research hosts

Summary

The short version

Earth Lusca is a threat actor attributed to State-sponsored, I-Soon, assessed as information theft and espionage-motivated. Its recorded targeting runs to gambling companies, government institutions, education, media and entertainment and adjacent sectors across 15 countries in the open reporting we hold — United Arab Emirates among them.

Across 44 attributed ATT&CK techniques we resolve 14 distinct behaviours — the things they do that a detection can be written against. The two that account for most of their observed tradecraft are discovery command burst on one host and valid account abuse or account creation. Their toolkit is 9 named items and not one of them is unique to this actor — everything they are reported to use is sold, published or shared between groups. That makes tooling useless as an identifier here, and the behaviours above carry the whole weight.

For a Gulf defender the relevant line is the victimology: United Arab Emirates appear in the reporting behind this record. That is evidence of past targeting, not a forecast, and it is drawn from what vendors chose to publish — an actor working quietly in a market nobody reports on looks identical to one that is absent.

As MITRE describes them: “Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication companies, religious organizations, and other civil society groups. Earth Lusca's tools closely resemble those used by Winnti Umbrella, but the group appears to operate separately from Winnti. Earth Lusca has also been observed targeting cryptocurrency payment platforms and cryptocurrency exchanges in what are likely financially motivated attacks.” — MITRE ATT&CK, CC BY 4.0.

On the name. “Earth Lusca” labels a cluster of related activity tracked under one name — not a verified organisation. Whether one team, several contractors or a rotating cast sits behind it is not something this record establishes, and the vendor names below are separate groupings that only mostly overlap.

02 — The detection plan

What to detect, ranked by what survives their retooling

Most actor profiles hand you indicators that expire in days. These are the behaviours the actor cannot drop without changing how they operate, each with the reason it holds. Weight is our own: how much of the actor's observed tradecraft the behaviour accounts for.

D2

Persistence pointing into world-writable staging

Tier 1–2

The persistence mechanism and the directory it points at both outlive the payload. The discriminator is the TARGET PATH, not the task or key name, which the actor can change freely.

8 techniques · weight 5

D3

Signed binary side-loading an unsigned library

Tier 1–3

The trusted executable is the constant; the dropped library changes every build. Detecting the LOAD relationship survives retooling that every hash and filename rule misses.

6 techniques · weight 5

D4

Credential access against LSASS

Tier 3–5

Few legitimate processes read LSASS memory, so precision is high in most estates once the agents that do are excluded.

2 techniques · weight 5

D5

User-facing application spawning an interpreter

Tier 3

The delivery wrapper changes constantly; an office, archive or browser process parenting a shell is the same shape across all of them.

8 techniques · weight 5

D1

Sanctioned SaaS platform as command or exfil channel

Tier 5–6

Defeats egress-domain control outright — the destination is a platform the estate already permits, so no blocklist and no TLD heuristic will see it.

7 techniques · weight 4

D6

Vendor-suggestive name outside that vendor's paths

Tier 4

Encodes the naming RULE rather than the filenames, so it survives every rename. The convention is a habit; the names are inventory.

6 techniques · weight 4

D7

Encoded or obfuscated interpreter invocation

Tier 3

The command-line SHAPE — the flag combination, not the payload — is stable for months to years and cheap to match.

8 techniques · weight 4

D12

Execution brokered through WMI or a native API

Tier 3

Chosen to avoid a shell, so command-line rules miss it entirely. The broker is a stable choice; what it runs is not.

6 techniques · weight 4

D8

Living-off-the-land download of a second stage

Tier 5

The set of system binaries that can fetch a file is small and changes with the OS, not with the actor.

5 techniques · weight 3

D9

Collection staged into an archive before egress

Tier 3

Staging is a step the actor cannot skip, and it happens before the data leaves — the last cheap place to catch it.

7 techniques · weight 3

D10

Exploitation of an internet-facing service

Context

Not a durable behavioural signature but the entry vector for a large public estate — worth an exposure control even where the detection is weak.

3 techniques · weight 3

D11

Protocol tunnelling or an internal proxy hop

Tier 5

The tunneller is a tool choice that persists for months, and the traffic shape is visible even when the payload is not.

8 techniques · weight 3

D13

Valid account abuse or account creation

Tier 5

Produces no malware event at all — the only trace is in identity telemetry, which is why an endpoint-only programme has a blind spot exactly here.

10 techniques · weight 3

D14

Discovery command burst on one host

Context

No single discovery command is worth an alert. The DENSITY is — several distinct recon binaries on one host inside an hour is a shape ordinary use does not produce.

17 techniques · weight 2

How to score it

No single behaviour here is worth waking someone. Summed weights of 6 on one host inside a window is an alert; 10 is an incident. The pair that most reliably means this actor rather than commodity crime is Persistence pointing into world-writable staging + Signed binary side-loading an unsigned library — seen together, treat as an incident regardless of total.

03 — Tooling

9 named tools, and what each is for

Purpose is derived, not asserted: each tool's own ATT&CK techniques are resolved to tactics, and the tactics it spends most of its techniques in are what it is for.

Actor-specific means we have no record of it outside this actor's reporting — those are the names that identify them. Commodity covers everything sold, published or shared: Cobalt Strike and Brute Ratel are licensed red-team software every pentester owns, Mimikatz and Impacket are public, and backdoors like ShadowPad circulate between unrelated groups. Finding a commodity tool tells you far less, which is exactly why the split is drawn. ATT&CK's own “malware vs tool” type answers a different question — whether the software is malicious — so it is not used for this.

Commodity and dual-use — 9 items

Cobalt Strike Commodity

Moving between hosts and gathering data.

S0154  ·  73 techniques  ·  Lateral Movement, Collection, Privilege Escalation
PowerSploit Commodity

Credential theft and gathering data.

S0194  ·  28 techniques  ·  Credential Access, Collection, Persistence
ShadowPad Commodity

Moving data out and remote control.

S0596  ·  21 techniques  ·  Exfiltration, Command and Control, Discovery
Mimikatz Commodity

Credential theft and moving between hosts.

S0002  ·  17 techniques  ·  Credential Access, Lateral Movement, Persistence

Remote control and evading defences.

S0430  ·  8 techniques  ·  Command and Control, Stealth
NBTscan Commodity

Credential theft and network reconnaissance.

S0590  ·  5 techniques  ·  Credential Access, Discovery
certutil Commodity

Gathering data and remote control.

S0160  ·  4 techniques  ·  Collection, Command and Control, Defense Impairment
Tasklist Commodity

Network reconnaissance.

S0057  ·  3 techniques  ·  Discovery
Nltest Commodity

Network reconnaissance.

S0359  ·  3 techniques  ·  Discovery
No data

File hashes for Earth Lusca’s own tooling

We hold none. Our corpus carries 9,780 hashes, but they come from live feeds covering current commodity campaigns — not the decade-old actor-specific backdoors in the list above. ATT&CK itself publishes no sample hashes; it is a technique knowledge base. Where a sample would have to come from a third party’s family tag rather than from this actor’s reporting, we leave the row empty instead of implying an attribution we cannot support.

File hashes — commodity families — 9 held

⚠ These are samples of tools this actor is reported to use, not samples tied to this actor. Cobalt Strike and China Chopper are used by hundreds of groups and by red teams; a match here is evidence about the tool, not about Earth Lusca. Published because a hunt starting point is still worth having, labelled so it cannot be mistaken for attribution.

HashTypeFamilyFirst seen
fe11b199ada23d5ac25efc4215e67f4ff617ccb4d429eb64412072687367ca1csha256Cobalt Strike2026-06-22
ed7087e3afba4b320bdf04f32d3a6c567effd3d18a97682968e567000e70b335sha256Cobalt Strike2026-06-22
eb14d9e35a3bf0a933297f861bee0be9e6b9061fe4573a81ac92b71d55b6474fsha256Cobalt Strike2026-06-22
e7aff6a55a7866776272d9913dfbf9d7db33fc9de6aced22f2a195feebb0e85fsha256Cobalt Strike2026-06-22
cd99e83d241cfbb41bfcd0bc622a87d16268e710ca7d736d0c5f44774e0056e2sha256Cobalt Strike2026-06-22
c937eca7c4c9b98df9257d986e666d25411aac5fa39d21f7018dd2e1663f0c76sha256Cobalt Strike2026-06-22

04 — Coverage, honestly counted

Where the 44 techniques actually go

Of the techniques attributed to Earth Lusca, 31 fold into the detection plan above, 9 describe preparation you cannot see from inside your network, and 4 are uncatalogued — we have not yet placed them. That last number is published on purpose; it is the honest size of the gap.

Execution8
Resource Development8
Discovery7
Stealth6
Initial Access3
Persistence3
Credential Access2
Collection1
Command and Control1
Defense Impairment1
Exfiltration1
Lateral Movement1
Privilege Escalation1
Reconnaissance1

05 — The chain

The order it happens in

The same techniques as above, sequenced. Useful for deciding where to spend a detection: the earlier a tactic sits, the more of the intrusion you still get to prevent.

01
Reconnaissance
1 technique
02
Resource Development
8 techniques
03
Initial Access
3 techniques
04
Execution
8 techniques
05
Persistence
3 techniques
06
Privilege Escalation
1 technique
07
Credential Access
2 techniques
08
Discovery
7 techniques
09
Lateral Movement
1 technique
10
Collection
1 technique
11
Command and Control
1 technique
12
Exfiltration
1 technique
13
Stealth
6 techniques
14
Defense Impairment
1 technique

06 — Tradecraft artefacts

Concrete strings, each with the report it came from

Pulled from primary vendor research and kept attributed. These are hunt starting points, not detections — a path an actor used once is worth a query, not a rule.

ArtefactKind First reported byDate
%programdata%\Microsoft file path Eset 2026-06-16
%public%\log.dll file path ESET 2025-03-20
%public%\music\sam.hive file path ESET 2025-03-20
%public%\music\system.hive file path ESET 2025-03-20
%public%\music\temp.tmp file path ESET 2025-03-20
%public%\task.exe file path ESET 2025-03-20
%systemroot%\Fonts file path Eset 2026-06-16
%systemroot%\Fonts\ file path Eset 2026-06-16
%systemroot%\Fonts\X1B5206BDC1743DD.dat file path Eset 2026-06-16
%windir%\Fonts\KW1B5206BDC1743FP.dat file path Eset 2026-06-16
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vds.exe registry Eset 2026-06-16
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vds.exe\debugger registry Eset 2026-06-16

07 — Sourcing, graded

Who told us, and how much that is worth

NATO Admiralty grading. The letter is the source's reliability, the number the credibility of the claim. We separate primary vendor research from outlets reporting on it, because ten articles derived from one report is one report.

GradeSourceBasis
B2MITRE actor record29 references across 18 distinct research hosts
B2Eset4 items — primary vendor research
C3Dark Reading3 items — reporting on other vendors' research
B2Group-IB2 items — primary vendor research
C3The Hacker News2 items — reporting on other vendors' research
C3BleepingComputer1 item — reporting on other vendors' research
B2Trend Micro1 item — primary vendor research
C4otx6 indicators; 0 of 6 corroborated by a second source
—Estate telemetryno data — absent, not negative

13 items · 6 outlets · 31% of reporting traces to a single outlet

08 — What we do not know

The gaps, published

Every vendor profile has these. Most omit them, which leaves you unable to tell a quiet actor from an unobserved one.

NO DATA

C2 URI fingerprints

No URI paths, headers or beacon sequences for any family we hold. The 6 URLs in our indicator set are unanalysed atomic values, not fingerprints.

NO DATA

Infrastructure

No domains are attributed to this actor in our holdings, so no naming convention, TLD preference or hosting pattern can be derived.

09 — Outlook

Forward judgements

Probability language is ICD 203. Likelihood and confidence are stated separately: how likely we think it is, and how good our basis is for thinking so.

Remains active
our newest reporting on this actor is from 2026-07-23, 58 days ago
ALMOST CERTAINconf HIGH
sanctioned SaaS platform as command or exfil channel continues
a tier-5–6 behaviour, which outlives the tooling that expresses it
VERY LIKELYconf MODERATE

10 — Primary sources

Every reference behind this record

29 of them. Published in full so the page can be checked rather than believed.

hello.global.ntthttps://hello.global.ntt/-/media/ntt/global/insights/white-papers/the-operations-of-winnti-grouptrendmicro.comhttps://www.trendmicro.com/content/dam/trendmicro/global/en/research/22/a/earth-lusca-employs-sorecordedfuture.comhttps://www.recordedfuture.com/chinese-group-tag-22-targets-nepal-philippines-taiwanquery.prod.cms.rt.microsoft.comhttps://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RWMFIimedia-exp1.licdn.comhttps://media-exp1.licdn.com/dms/document/C561FAQHhWFRcWmdCPw/feedshare-document-pdf-analyzed/0/sentinelone.comhttps://www.sentinelone.com/wp-content/uploads/2021/08/SentinelOne_-SentinelLabs_ShadowPad_WP_V2pwc.co.ukhttps://www.pwc.co.uk/issues/cyber-security-services/research/chasing-shadows.htmlcrowdstrike.comhttps://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exdecoded.avast.iohttps://decoded.avast.io/luigicamastra/backdoored-client-from-mongolian-ca-monpasspwc.comhttps://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospecgo.recordedfuture.comhttps://go.recordedfuture.com/hubfs/reports/cta-2023-0808.pdfsecurelist.comhttps://securelist.com/apt-annual-review-2021/105127securelist.comhttps://securelist.com/apt-trends-report-q2-2021/103517ncsc.gov.ukhttps://www.ncsc.gov.uk/static-assets/documents/malware-analysis-reports/jolly-jellyfish/NCSC-MApwc.comhttps://www.pwc.com/gx/en/issues/cybersecurity/cyber-threat-intelligence/cyber-year-in-retrospecyoutube.comhttps://www.youtube.com/watch?v=-7Swd1ZetiQwelivesecurity.comhttps://www.welivesecurity.com/en/eset-research/operation-fishmedley/apt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=0730437a-1b64-4777-a920-64bbe97214c0crowdstrike.comhttps://www.crowdstrike.com/blog/overwatch-exposes-aquatic-panda-in-possession-of-log-4-shell-exapt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=fd9f43c9-80bf-4abc-9345-f5332e26eeaatrendmicro.comhttps://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.htmltrendmicro.comhttps://www.trendmicro.com/en_us/research/24/b/earth-lusca-uses-geopolitical-lure-to-target-taiwtrendmicro.comhttps://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.htmlmicrosoft.comhttps://www.microsoft.com/en-us/security/blog/2024/02/14/staying-ahead-of-threat-actors-in-the-aattack.mitre.orghttps://attack.mitre.org/groups/G1006/apt.etda.or.thhttps://apt.etda.or.th/cgi-bin/showcard.cgi?u=4de6af3d-8242-44c6-80eb-9eee83a62823trendmicro.comhttps://www.trendmicro.com/en_us/research/21/g/biopass-rat-new-malware-sniffs-victims-via-live-srecordedfuture.comhttps://www.recordedfuture.com/chinese-group-tag-22-targets-nepal-philippines-taiwan/sentinelone.comhttps://www.sentinelone.com/labs/unmasking-i-soon-the-leak-that-revealed-chinas-cyber-operations

Run it against your own estate

Which of these 14 behaviours do you already detect?

The library is the part we can publish. The platform runs the same detection plan against your own estate, tells you which of these behaviours you already cover, and retro-hunts the rest — on your hardware, with nothing leaving the building.

❯ ESC

THE TRACE · LOCAL INFERENCE · REASONING SHOWN STEP-BY-STEP

Try: “which of our vendors were hit by qilin” · “fortios exposure” · “what changed on our perimeter this week”