Threats Tagged 'misp-galaxy:threat-actor="earth lusca"'
View all threats tagged with 'misp-galaxy:threat-actor="earth lusca"'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'misp-galaxy:threat-actor="earth lusca"'
Click on any threat for detailed analysis and mitigation recommendations
Earth Lusca, a threat actor linked to China, is reported to use the KTLVdoor backdoor for multiplatform intrusion. This backdoor enables persistent access across different operating systems, facilitating espionage or data exfiltration. Although no known exploits in the wild or patches are currently available, the threat actor's activity indicates targeted payload delivery. The severity is assessed as low based on current information, but the lack of patches and the multiplatform nature warrant attention. European organizations should be aware of potential indirect risks, especially those with ties to Chinese entities or operating in sensitive sectors. Mitigation should focus on enhanced monitoring for unusual backdoor activity and network segmentation. Countries with significant Chinese business presence or geopolitical interest in China-related cyber activities are more likely to be affected. Overall, defenders should prioritize threat intelligence integration and proactive detection mechanisms to mitigate potential future exploitation. Join the discussion | CIRCL OSINT Feed | 09/04/2024, 00:00:00 UTC Added: 05/27/2025, 11:06:10 UTC |
Showing 1 to 1 of 1 result