Trend Micro reported that the China-aligned threat group Earth Lusca targeted organizations in Taiwan with politically themed social-engineering lures tied to cross-strait tensions and the island’s election period. The campaign used documents and decoy content crafted to appear relevant to current geopolitical developments, aiming to entice victims into opening malicious files and initiating compromise.
The activity was attributed to a broader cyber-espionage effort focused on Taiwan, with the attackers seeking access to targeted environments for intelligence collection. Trend Micro said the operation reflected Earth Lusca’s established pattern of using timely regional issues to improve phishing success and maintain persistent access against government and other organizations of strategic interest.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Trend Micro published research describing an Earth Lusca campaign that used geopolitical lures to target Taiwan ahead of its elections. The report indicates the activity was active before the election period, but the reference provides no specific earlier event dates.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.