← Back to all threat actors

Earth Lusca

Also known as TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
Tracked as G1006

Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.

How we source and review actor profiles
Motivation
nation-state
Status
Active

Threat intelligence assessment

At a glance

Facts

  • Rust-based information stealer targeting macOS
  • Named after login page at C2 root called 'Amnesia Panel' with Russian error messages

Activity timeline

Facts

  • Disclosed by Jamf Threat Labs in August 2026

Attribution assessment

Facts

  • Shares behavioral similarities with ClickLock Stealer, another macOS stealer that uses ClickFix technique
  • Overall objectives consistent with Atomic Stealer, MacSync, and CrashStealer

Operational playbook

Facts

  • Multi-stage deployment: shell script dropper, Rust infostealer, and stream_module for remote control
  • Uses builder-driven configuration modifiable at build level without code changes
  • Operator receives live 3fps screencast and can control browser with full input set

Initial access and identity targets

Facts

  • Spread via counterfeit GitHub download page titled 'Download for macOS' claiming to be from verified publisher
  • Employs ClickFix-style lure instructing users to copy and paste Base64-encoded command into macOS Terminal

Capabilities and evasion

Facts

  • Hijacks Chromium web browsers to steal session data
  • Harvests Keychain, browser data, Apple Notes, and Telegram sessions
  • Targets 16 Chromium-family browsers including Chrome, Brave, Arc, and Edge
  • Steals cookies, login data, web data, history, bookmarks, local state, preferences, and extensions directory
  • Clipboard-hijacking (clipper) module targeting Bitcoin, Bitcoin Cash, Ethereum, TRON, Litecoin, Monero, Solana, Ripple, and Cosmos
  • Performs host reconnaissance and geolocation profiling
  • Displays native prompt to capture system password, validated against local directory service via dscl
  • Harvests files with extensions .txt, .pdf, .rtf, .doc, .wallet, .key, .jpg, .png, and .csv from Desktop, Documents, and Downloads
  • Uses TCC bypass flaw CVE-2020-9771 to target Safari cookies on macOS Catalina
  • Reads Chrome Safe Storage password from Keychain to recover master keys
  • Second-stage module enables interactive remote control over Chrome DevTools Protocol
  • Injects script to patch browser fingerprinting APIs to avoid automation detection
  • Supports headless mode for seven Chromium browsers: Chrome, Brave, Edge, Arc, Opera, Vivaldi, Chromium
  • Spawns WebSocket relay channel for operator commands and status reporting

Infrastructure patterns

Facts

  • C2 endpoints include 'debug.allllowef.space/send/'
  • Dropper script hosted on remote server
  • Password-protected ZIP archive hosted on remote server
  • Staged data archived in directory with 25 random alphanumeric characters under '/tmp'

Communication and pressure channels

Facts

  • C2 commands trigger payload to fetch second-stage binary
  • 'remote_stream' command initiates browser hijacking stage
  • Operator commands translated to Chrome DevTools Protocol calls in real time
  • Status and screencast reported back to C2 endpoint via WebSocket

Observed targeting

Facts

  • macOS-oriented malware

Defender guidance

Facts

  • Differs from typical stealers through builder-driven configuration and OS version-branched logic
  • Remote-control second stage allows attackers to steal cookies and evade detection through fingerprinting API patching
  • Establishes persistence via root LaunchDaemon impersonating Apple's crash reporting service

Reported detail

Facts

  • AmnesiaStealer is a Rust-based macOS stealer deployed via counterfeit GitHub pages using ClickFix social engineering to trick users into running Terminal commands.
  • The malware operates in three stages: a shell script dropper, a Rust infostealer harvesting credentials and browser data, and a remote-control module providing live browser hijacking via Chrome DevTools Protocol.
  • It targets Chromium-based browsers and can exfiltrate cookies, login credentials, and session data while allowing operators to remotely control authenticated browser sessions at approximately 3 frames per second.
  • The malware uses social engineering to capture the macOS system password, then reuses it to unlock Keychain, access browser storage, and establish persistence through a fake Apple crash reporting service.
  • AmnesiaStealer's builder-driven configuration, version-specific OS bypasses, and sophisticated browser fingerprinting evasion techniques distinguish it from other macOS stealers like Atomic Stealer and MacSync.

Activity timeline

A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.

Cataloged
Indicator3 indicators cataloged

Types: domain, tool.

Cataloged
IdentityAlias: TAG-22

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: Charcoal Typhoon

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: CHROMIUM

Reviewed identity mapping approved on this date.

Cataloged
IdentityAlias: ControlX

Reviewed identity mapping approved on this date.

Cataloged
IdentityTracking identifier: G1006

Reviewed identity mapping approved on this date.

First observed
CVECVE-2020-9771 linked to this actor

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Identity and attribution

Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.

Name map

Earth LuscaCanonical Name
CHROMIUMAlias
Charcoal TyphoonAlias
ControlXAlias
TAG-22Alias
G1006Tracking Id

Loading CVEs, techniques, indicators, malware, victims, and activity...