Earth Lusca Expands Arsenal with Windows SprySOCKS Malware

Chinese threat actor Earth Lusca has upgraded its malware arsenal with Windows SprySOCKS, a sneaky tool that lets hackers secretly send commands to compromised devices, allowing them to fly under the radar. This latest move has been linked to a string of high-profile attacks on government organizations worldwide.

https://osintsights.com/earth-lusca-expands-arsenal-with-windows-sprysocks-malware?utm_source=mastodon&utm_medium=social

#EarthLusca #WindowsSprysocksMalware #Sprysocks #China #Government

Earth Lusca Expands Arsenal with Windows SprySOCKS Malware

Learn how Earth Lusca uses Windows SprySOCKS malware to divert TCP traffic and issue commands. Discover the threat actor's tactics and protect your organization now from cyber attacks.

OSINTSights

Read more about the latest research I did with my talented colleague @jaromirhorejsi ! We exposed a previously unreported and new malware family we named KTLVdoor, used by Chinese-speaking threat actors including #EarthLusca ! More than 50 C2s have been found to communicate with this #malware family !

https://www.trendmicro.com/en_us/research/24/i/earth-lusca-ktlvdoor.html

#cyberespionage #china

Earth Lusca Uses KTLVdoor Backdoor for Multiplatform Intrusion

Trend Micro

Trend Micro reports on a new China-nexus cyberespionage group (dubbed Earth Krahang) that primarily targets Southeast Asia and then Europe, America, and Africa. It has multiple connections to another Chinese APT Earth Lusca (aka Aquatic Panda, Bronze University, Charcoal Typhoon, RedHotel) and potential links to i-SOON. Trend Micro was able to retrieve multiple files from Earth Krahang’s servers, including samples, configuration files, and log files from its attack tools. MITRE ATT&CK TTPs and IOC provided. 🔗 https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html

#EarthKrahang #cyberespionage #EarthLusca #AquaticPanda #CharcoalTyphoon #RedHotel #China #APT #IOC #threatintel #MITREATTACK

Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks

Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.

Trend Micro
Very proud to release my latest research which exposes a Chinese-speaking threat actor to attacks on Taiwan before the national elections - https://www.trendmicro.com/en_us/research/24/b/earth-lusca-uses-geopolitical-lure-to-target-taiwan.html #APT #cyberespionage #isoon #i-soon #EarthLusca
Earth Lusca Uses Geopolitical Lure to Target Taiwan Before Elections

During our monitoring of Earth Lusca, we noticed a new campaign that used Chinese-Taiwanese relations as a social engineering lure to infect selected targets.

Trend Micro