Earth Lusca has used ProcDump to obtain the hashes of credentials by dumping the memory of the LSASS process.3
group
Earth Lusca G1006
- Created
- 1 July 2022
- Last modified
- 31 July 2026
- Aliases
- Earth Lusca · TAG-22 · Charcoal Typhoon · CHROMIUM · ControlX
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated.[1]
Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.[2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G1006
Earth Lusca has used a DCSync command with Mimikatz to retrieve credentials from an exploited controller.4
Earth Lusca has used Tasklist to obtain information from a compromised host.5
Earth Lusca used the command ipconfig to obtain information about network configurations.6
Earth Lusca used the command powershell “Get-EventLog -LogName security -Newest 500 | where {$_.EventID -eq 4624} | format-list -
property * | findstr “Address”” to find the network information of successfully logged-in accounts to discovery addresses of other machines. Earth Lusca has also used multiple scanning tools to discover other machines within the same compromised network.7
Earth Lusca used Base64 to encode strings.8
Standing G1006
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
81st percentile · 81% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tactics spanned or fewer.
81st percentile · 81% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
52nd percentile · 52% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G1006
1670 distinct rules cover the 44 techniques recorded for this group. The 1924 technique-to-rule mappings resolve to 1670 distinct rules, because one rule can cover several techniques. 1127 Sigma · 543 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org