#EarthLusca
Windows variants of SprySOCKS backdoor linked to China-backed Earth Lusca reveal advanced stealth tactics in cyber espionage. #CyberSecurity #SprySOCKS #EarthLusca #Malware thedailytechfeed.com/china-linked...
June 16, 2026 at 10:02 AM
Very proud to release my latest research which exposes a Chinese-speaking threat actor to attacks on Taiwan before the national elections - www.trendmicro.com/en_us/resear... #APT #cyberespionage #isoon #EarthLusca #i-soon
February 26, 2024 at 9:38 AM
ESET found Windows SprySOCKS backdoor variants used against government orgs in Taiwan, Thailand, Pakistan, and Honduras, with high-confidence attribution to Earth Lusca and possible ties to CVE-2023-24932. #Taiwan #EarthLusca #SprySOCKS
Windows version of SprySOCKS Linux malware used to attack govt orgs
ESET found Windows variants of the SprySOCKS backdoor used in attacks against government organizations in Taiwan, Thailand, Pakistan, and Honduras, and attributed the activity to Earth Lusca. The malware adds kernel-level stealth, multiple persistence methods, and TCP traffic diversion, with possible links to a UEFI bootkit component tied to CVE-2023-24932. #SprySOCKS #EarthLusca #FishMonger #AquaticPanda #RedDev10 #TAG22 #CVE202324932 #BlackLotus
www.hendryadrian.com
June 16, 2026 at 10:00 AM
Earth Lusca, a China-linked threat actor since 2019, targets government, media, telecom, academia, and crypto platforms using advanced tools like KTLVdoor and ShadowPad with cloud-based rotating C2 infrastructure. #China #EarthLusca #KTLVdoor
APT Profile – Earth Lusca
Earth Lusca (aka FishMonger) is a China-linked threat actor active since 2019 that conducts long‑term cyber-espionage against government, media, telecommunications, academic, and religious organizations while also running financially motivated campaigns against cryptocurrency platforms. Recent campaigns show expanded tooling and tradecraft — including the new Go-based, multi-platform backdoor KTLVdoor, extensive use of ShadowPad/Winnti toolsets, and a large, cloud-hosted, rotating C2 infrastructure to maintain stealth. #EarthLusca #KTLVdoor
www.hendryadrian.com
March 11, 2026 at 4:40 PM
🚨 Chinese APT drama: Chengdu 404 (#RedGolf/#APT41) suing i-SOON (#RedHotel/#EarthLusca) over a "software development dispute" 🙃

Particularly interesting given RedHotel's use of malware families suspected to be originally developed in part by RedGolf/APT41 operators (e.g. ShadowPad/Winnti)
i-SOON: Another Company in the APT41 Network
A lawsuit casts light on the ecosystem of IT companies related to Chengdu 404, the company allegedly behind Chinese state-sponsored hacking group APT41.
nattothoughts.substack.com
October 27, 2023 at 1:28 PM
📰 Kelompok Hacker 'Earth Lusca' Rilis Varian Windows dari Malware SprySOCKS untuk Serang Pemerintah

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/06/16/malware-linux-sprysocks-kini-serang-windows/

#ear
th#earthLusca #esete#hackern#jaringane#kernelu#komputerx#linuxa#malwarer#pemerintah
June 16, 2026 at 11:54 AM
Read more about the latest research I did with my talented colleague Jaromir ! We exposed a previously unreported and new malware family we named KTLVdoor, used by Chinese-speaking threat actors including #EarthLusca - More than 50 C2s ! #cyberespionage - www.trendmicro.com/en_us/resear...
September 4, 2024 at 8:05 AM
Read more about the latest research I did with my talented colleague Jaromir ! We exposed a previously unreported and new malware family we named KTLVdoor, used by Chinese-speaking threat actors including #EarthLusca - More than 50 C2s ! #potatoespionage - www.trendmicro.com/en_us/resear...
September 4, 2024 at 8:58 AM