China-linked threat actor Earth Lusca expanded its operations globally while continuing to concentrate on Southeast Asia, Central Asia, and the Balkans, according to Trend Micro. Researchers recovered and decrypted a previously unseen Linux backdoor dubbed SprySOCKS from the group’s delivery infrastructure, linking it to campaigns targeting government departments involved in foreign affairs as well as organizations in the technology and telecommunications sectors.
Trend Micro said SprySOCKS appears to be a Linux adaptation of the open-source Windows backdoor Trochilus, with an interactive shell resembling Linux Derusbi and a command-and-control protocol similar to RedLeaves RAT. The malware uses a two-part architecture consisting of a loader and an encrypted main payload, and multiple version markers indicate it remains under active development. Investigators also observed Earth Lusca using Cobalt Strike for lateral movement and aggressively exploiting public-facing servers through server-side N-day vulnerabilities to gain access.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Researchers obtained an encrypted file from an Earth Lusca delivery server, recovered the original loader from VirusTotal, and decrypted a previously unseen Linux backdoor they named SprySOCKS. The malware was described as a Linux adaptation of the open-source Windows backdoor Trochilus and had only been observed in Earth Lusca operations.
Trend Micro reported that Earth Lusca broadened its operations globally during the first half of 2023, while continuing to focus mainly on Southeast Asia, Central Asia, and the Balkans. Its recent campaigns primarily targeted government departments involved in foreign affairs, technology, and telecommunications.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.