APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Earth Lusca (aka Earth Lusca, TAG-22) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Earth Lusca
G1006
APT
CN · China
AKA
TAG-22 · FISHMONGER
CrowdStrike
:
AQUATIC PANDA
Mandiant
:
UNC2478
Microsoft
:
Charcoal Typhoon
MITRE
:
G1006
Proofpoint
:
TA423
PwC
:
RedHotel
Targets
15
Sectors
11
Threat types
1
GIRs covered
0/480
Active since
2019
Pin to atlas
Watch
Share
Export
Also tracked as
6 vendor names · 2 other aliases
Open Rosetta Stone
CrowdStrike
AQUATIC PANDA
Mandiant
UNC2478
Microsoft
Charcoal Typhoon
MITRE
G1006
Proofpoint
TA423
PwC
RedHotel
UNATTRIBUTED ALIASES
TAG-22
FISHMONGER
Victimology
Geographic footprint · 15 countries
Region filter
Export
origin · China
targeted countries · 15
AMERICAS ·
2
Brazil
·
United States
ASIA ·
9
Bhutan
·
Hong Kong
·
Indonesia
·
India
·
Japan
·
Mongolia
·
Philippines
·
Pakistan
·
Taiwan
EUROPE ·
3
Germany
·
Spain
·
France
AFRICA ·
1
South Africa
Sectors targeted
11 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Financial Services
74 actors
Cryptocurrency
21 actors
Telecom
72 actors
NGOs & Dissidents
56 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Consulting / Professional Services
35 actors
Industrials / Engineering
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 33 techniques
Resource Development
· 2
T1583.004
Server
T1583.006
Web Services
Initial Access
· 3
T1189
Drive-by Compromise
Execution
· 7
T1047
Windows Management Instrumentation
Persistence
· 2
T1543.003
Windows Service
Credential Access
· 2
T1003.001
LSASS Memory
Discovery
· 7
T1007
System Service Discovery
T1016
System Network Configuration Discovery
Lateral Movement
· 1
T1210
Exploitation of Remote Services
Collection
· 1
T1560.001
Archive via Utility
Exfiltration
· 1
T1567.002
Exfiltration to Cloud Storage
Command And Control
· 1
T1090
Proxy
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 5
T1027
Obfuscated Files or Information
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
33 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1190
Exploit Public-Facing Application
T1566.002
Spearphishing Link
T1053.005
Scheduled Task
T1059.001
PowerShell
T1059.005
Visual Basic
T1059.006
Python
T1059.007
JavaScript
T1204.001
Malicious Link
T1547.012
Print Processors
T1003.006
DCSync
T1018
Remote System Discovery
T1033
System Owner/User Discovery
T1049
System Network Connections Discovery
T1057
Process Discovery
T1482
Domain Trust Discovery
T1027.003
Steganography
T1036.005
Match Legitimate Resource Name or Location
T1140
Deobfuscate/Decode Files or Information
T1218.005
Mshta