Home · Wiki · Entities & Threat Actors
created: 2026-09-24 · updated: 2026-09-24 · type: entity · tags: [apt-group, nation-state] · confidence: high · affected_sectors: [] · au_impact: false

Earth Lusca

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States.

Attribute Detail
ATT&CK ID G1006
Aliases TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
Attribution China
Class state
Active since
ATT&CK entry created 2022-07-01
Techniques mapped 53

Attribution — as claimed

Stated by MITRE ATT&CK (state attribution).

Known TTPs

Technique Name
T1003.001 LSASS Memory
T1003.006 DCSync
T1007 System Service Discovery
T1016 System Network Configuration Discovery
T1018 Remote System Discovery
T1027 Obfuscated Files or Information
T1027.003 Steganography
T1033 System Owner/User Discovery
T1036.005 Match Legitimate Resource Name or Location
T1047 Windows Management Instrumentation
T1049 System Network Connections Discovery
T1053.005 Scheduled Task

(First 12 of 53 ATT&CK-mapped techniques.)

Related Pages

  • Mitre Attack — the framework this page's data is drawn from
  • Ke3Chang — China-linked actor, same attribution class
  • Mustang Panda — China-linked actor, same attribution class
  • Salt Typhoon — China-linked actor, same attribution class

Provenance

Stub generated from MITRE ATT&CK G1006 on 2026-09-24. ATT&CK is the publisher of this page's technique and alias data; the attribution wording above is ATT&CK's, not this wiki's.