Earth Lusca is a China-linked cyber espionage threat actor active since at least 2021 and widely tracked under aliases including FishMonger, Aquatic Panda, Charcoal Typhoon, RedHotel, TAG-22, Red Dev 10, Chromium, and ControlX. The cluster is assessed as part of the broader Winnti ecosystem, and multiple reports associate FishMonger/Earth Lusca with the Chinese contractor I-SOON. The actor conducts long-term intelligence collection operations primarily against government entities, especially organizations involved in foreign affairs, technology, and telecommunications, with additional historical targeting of universities and other public-sector institutions. Earth Lusca is known for using multiple initial access routes, including spear-phishing, watering-hole operations, and exploitation of public-facing applications and N-day vulnerabilities in enterprise software and edge infrastructure. Post-compromise activity includes web shell deployment, use of ShadowPad and Cobalt Strike, and lateral movement within victim environments. The group has also used Linux Winnti and other backdoors for sustained access. A defining capability is the SprySOCKS malware family, first documented as a Linux backdoor and later expanded to Windows. SprySOCKS is derived from the open-source Trochilus codebase and supports interactive shell access, system reconnaissance, file operations, service and process control, SOCKS proxying, and optional surveillance functions such as keylogging and clipboard capture. The Windows variants, known as WIN_DRV and WIN_PLUS, significantly increased the actor’s stealth and persistence on Windows hosts. WIN_DRV uses DLL sideloading, scheduled-task persistence, process doppelganging, and kernel-mode components to hide processes, files, registry artifacts, and network connections, while also diverting specially crafted TCP traffic through arbitrary open ports to conceal the backdoor listener. WIN_PLUS abuses the Windows Print Spooler through print-processor persistence and also injects into svchost.exe for stealth. Limited reporting has also noted unconfirmed indications of possible UEFI bootkit use associated with CVE-2023-24932. Observed operations in 2023 and 2024 targeted government organizations in Honduras, Taiwan, Thailand, and Pakistan. Earlier reporting also tied the actor to campaigns focused on Southeast Asia, Central Asia, and the Balkans, with scattered activity in Latin America and Africa, and historical targeting of universities in Hong Kong during the 2019 protests. Earth Lusca’s tradecraft reflects a mature espionage operator emphasizing covert persistence, defense evasion, cross-platform tooling, and long-term access to sensitive governmental networks.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
81 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
32 malware families attributed to this actor across reporting.
27 additional families tracked in Mallory.
27 CVEs this actor has used in observed campaigns. 27 of them exploited in the wild.
ESET researchers also noted indications that some attacks may involve a UEFI bootkit component, possibly exploiting CVE-2023-24932, which could allow the malware to survive a complete operating system reinstall.
Infection sequences start with the exploitation of known security flaws in public-facing ... Microsoft Exchange Server (ProxyShell) ... servers to drop web shells and deliver Cobalt Strike for lateral movement.
Earth Lusca has used Mimikatz to exploit a domain controller via the ZeroLogon exploit (CVE-2020-1472).
Details on Exploited Vulnerabilities ... CVE-2016-5195 Linux kernel 7.0
Infection sequences start with the exploitation of known security flaws in public-facing ... Progress Telerik UI (CVE-2019-18935) ... servers to drop web shells and deliver Cobalt Strike for lateral movement.
22 more CVEs tied to this actor tracked in Mallory.
37 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced for TTP overlap with similar Chinese-origin post-exploitation tooling targeting government and education sectors.
Targeted government organizations using multiple malware families to improve stealth and persistence.
Conducting stealthy cyber-espionage operations using Windows variants of the SprySOCKS backdoor, including a kernel rootkit-capable variant that hides processes, files, connections, and registry keys and enables covert C2 over arbitrary open TCP ports. Activity was observed primarily against government organizations.
Chinese cyberespionage group expanding SprySOCKS from Linux to Windows, targeting primarily government entities and conducting espionage campaigns. The group is also known for watering-hole attacks and continued investment in stealth and persistence capabilities.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.