Threat actor · all actors
Aquatic PandaG0143 state
🇨🇳 CN
aka Aquatic Panda, Earth Lusca, CHROMIUM, ControlX, TAG-22, FISHMONGER, BRONZE UNIVERSITY, Red Dev 10, RedHotel, Charcoal Typhoon, BountyGlad, Red Scylla
Last updated: 2026-08-22
About this actor
Earth Lusca is a threat actor from China that targets organizations of interest to the Chinese government, including academic institutions, telecommunication companies, religious organizations, and other civil society groups. Earth Lusca's tools closely resemble those used by Winnti Umbrella, but the group appears to operate separately from Winnti. Earth Lusca has also been observed targeting cryptocurrency payment platforms and cryptocurrency exchanges in what are likely financially motivated attacks.
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Secureworkscolour-metal names
Recorded FutureTAG id
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 49 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2026 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2026-20929 | 5.9 | 7.5 | 0.0116 | 2026-01-13 | see CVE |
T1003OS Credential Dumping ↗T1003.001LSASS Memory ↗T1005Data from Local System ↗T1007System Service Discovery ↗T1021Remote Services ↗T1021.001Remote Desktop Protocol ↗T1021.002SMB/Windows Admin Shares ↗T1021.004SSH ↗T1027Obfuscated Files or Information ↗T1027.010Command Obfuscation ↗T1033System Owner/User Discovery ↗T1036Masquerading ↗T1036.004Masquerade Task or Service ↗T1036.005Match Legitimate Resource Name or Location ↗T1047Windows Management Instrumentation ↗T1059Command and Scripting Interpreter ↗T1059.001PowerShell ↗T1059.003Windows Command Shell ↗T1059.004Unix Shell ↗T1070Indicator Removal ↗T1070.003Clear Command History ↗T1070.004File Deletion ↗T1078Valid Accounts ↗T1078.002Domain Accounts ↗T1082System Information Discovery ↗T1087Account Discovery ↗T1105Ingress Tool Transfer ↗T1112Modify Registry ↗T1218System Binary Proxy Execution ↗T1218.011Rundll32 ↗T1518Software Discovery ↗T1518.001Security Software Discovery ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1550Use Alternate Authentication Material ↗T1550.002Pass the Hash ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1574Hijack Execution Flow ↗T1574.001DLL ↗T1574.006Dynamic Linker Hijacking ↗T1588Obtain Capabilities ↗T1588.001Malware ↗T1588.002Tool ↗T1595Active Scanning ↗T1595.002Vulnerability Scanning ↗T1654Log Enumeration ↗T1685Disable or Modify Tools ↗T1685.005Clear Windows Event Logs ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
SI-4 | 31 / 49 | 63% |
CM-6 | 30 / 49 | 61% |
AC-2 | 28 / 49 | 57% |
AC-3 | 28 / 49 | 57% |
AC-6 | 28 / 49 | 57% |
CM-2 | 26 / 49 | 53% |
SI-3 | 23 / 49 | 47% |
AC-5 | 21 / 49 | 43% |
CM-7 | 20 / 49 | 41% |
SI-7 | 20 / 49 | 41% |
CM-5 | 18 / 49 | 37% |
IA-2 | 18 / 49 | 37% |
CA-7 | 16 / 49 | 33% |
RA-5 | 13 / 49 | 27% |
SI-10 | 13 / 49 | 27% |
Co-occurring actors
- Ajax Security Team 1 shared CVEs
- APT29 1 shared CVEs
- APT38 1 shared CVEs
- Sandworm Team 1 shared CVEs
- Tonto Team 1 shared CVEs
- GOLD SOUTHFIELD 1 shared CVEs
- Scattered Spider 1 shared CVEs
- OilRig 1 shared CVEs
- Indrik Spider 1 shared CVEs
- Mustang Panda 1 shared CVEs
Similar actors
Similar TTPs
- Play 0.38
- Wizard Spider 0.34
- APT41 0.33
- Blue Mockingbird 0.33
- FIN8 0.33
Active in same years
- Operation Dream Job 1.00
- SolarWinds Compromise 1.00
- C0027 1.00
- SharePoint ToolShell Exploitation 1.00
- Ke3chang 1.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00