Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G1006
MITRE ATT&CK Group

Earth Lusca (G1006)

TAG-22Charcoal TyphoonCHROMIUMControlX
ShareXLinkedInRedditHN

[Earth Lusca](https://attack.mitre.org/groups/G1006) is a suspected China-based cyber espionage group that has been active since at least April 2019. [Earth Lusca](https://attack.mitre.org/groups/G1006) has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some [Earth Lusca](https://attack.mitre.org/groups/G1006) operations may be financially motivated.(Citation: TrendMicro EarthLusca 2022) [Earth Lusca](https://attack.mitre.org/groups/G1006) has used malware commonly used by other Chinese threat groups, including [APT41](https://attack.mitre.org/groups/G0096) and the [Winnti Group](https://attack.mitre.org/groups/G0044) cluster, however security researchers assess [Earth Lusca](https://attack.mitre.org/groups/G1006)'s techniques and infrastructure are separate.(Citation: TrendMicro EarthLusca 2022)

▪Techniques used (44)

T1583.006Web ServicesT1027.003SteganographyT1608.001Upload MalwareT1098.004SSH Authorized KeysT1003.006DCSyncT1059.005Visual BasicT1189Drive-by CompromiseT1018Remote System DiscoveryT1584.006Web ServicesT1059.007JavaScriptT1210Exploitation of Remote ServicesT1036.005Match Legitimate Resource Name or LocationT1140Deobfuscate/Decode Files or InformationT1583.001DomainsT1033System Owner/User DiscoveryT1547.012Print ProcessorsT1059.001PowerShellT1059.006PythonT1057Process DiscoveryT1053.005Scheduled TaskT1574.001DLLT1112Modify RegistryT1047Windows Management InstrumentationT1003.001LSASS MemoryT1218.005MshtaT1482Domain Trust DiscoveryT1567.002Exfiltration to Cloud StorageT1548.002Bypass User Account ControlT1588.002ToolT1007System Service DiscoveryT1204.002Malicious FileT1190Exploit Public-Facing ApplicationT1090ProxyT1027Obfuscated Files or InformationT1543.003Windows ServiceT1566.002Spearphishing LinkT1560.001Archive via UtilityT1583.004ServerT1049System Network Connections DiscoveryT1595.002Vulnerability ScanningT1016System Network Configuration DiscoveryT1588.001MalwareT1584.004ServerT1204.001Malicious Link

▪Software used (9)

S0002MimikatztoolS0194PowerSploittoolS0057TasklisttoolS0160certutiltoolS0154Cobalt StrikemalwareS0430Winnti for LinuxmalwareS0359NltesttoolS0590NBTscantoolS0596ShadowPadmalware
G1006on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.