← All Threat Actors
Threat Actor Profile

Earth Lusca

AQUATIC PANDA BountyGlad BRONZE UNIVERSITY Charcoal Typhoon CHROMIUM ControlX FISHMONGER G1006 Red Dev 10 Red Scylla RedHotel TAG-22
⚠ Critical Threat
Operation Deep Current, Edge-to-Core Intrusion
Origin China
Sponsor People's Republic of China (PRC)
Motivation Strategic intelligence gathering, political espionage, and theft of intellectual property related to defense and maritime technology.

Target Sectors

Government Agencies Defense Industrial Base (DIB) Aerospace and Maritime Technology Telecommunications Semiconductor Manufacturers Critical Infrastructure

Known TTPs

Exploitation of Edge Vulnerabilities (VPNs, Firewalls)
Living-off-the-Land (LotL) using PowerShell and WMI
Custom Web Shell deployment
Spear-phishing with specialized malware attachments
Credential Harvesting via LSASS memory dumping
Data Exfiltration via encrypted protocols (HTTPS/DNS)
Lateral Movement using SMB and RDP

External Resources

CISA Advisories ↗

Related Intelligence


LINK COPIED TO CLIPBOARD