created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false
Earth Lusca
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States.
| Attribute | Detail |
|---|---|
| ATT&CK ID | G1006 |
| Aliases | TAG-22, Charcoal Typhoon, CHROMIUM, ControlX |
| Attribution | China |
| Class | state |
| Active since | — |
| ATT&CK entry created | 2022-07-01 |
| Techniques mapped | 53 |
Attribution — as claimed
Stated by MITRE ATT&CK (state attribution).
Known TTPs
| Technique | Name |
|---|---|
T1003.001 |
LSASS Memory |
T1003.006 |
DCSync |
T1007 |
System Service Discovery |
T1016 |
System Network Configuration Discovery |
T1018 |
Remote System Discovery |
T1027 |
Obfuscated Files or Information |
T1027.003 |
Steganography |
T1033 |
System Owner/User Discovery |
T1036.005 |
Match Legitimate Resource Name or Location |
T1047 |
Windows Management Instrumentation |
T1049 |
System Network Connections Discovery |
T1053.005 |
Scheduled Task |
(First 12 of 53 ATT&CK-mapped techniques.)
Related Pages
- Mitre Attack — the framework this page's data is drawn from
- Ke3Chang — China-linked actor, same attribution class
- Mustang Panda — China-linked actor, same attribution class
- Salt Typhoon — China-linked actor, same attribution class
Provenance
Stub generated from MITRE ATT&CK G1006 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.