Also known as TAG-22, Charcoal Typhoon, CHROMIUM, ControlX
Tracked asG1006
Earth Lusca is a suspected China-based cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID-19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.
Operator commands translated to Chrome DevTools Protocol calls in real time
Status and screencast reported back to C2 endpoint via WebSocket
Observed targeting
Facts
macOS-oriented malware
Defender guidance
Facts
Differs from typical stealers through builder-driven configuration and OS version-branched logic
Remote-control second stage allows attackers to steal cookies and evade detection through fingerprinting API patching
Establishes persistence via root LaunchDaemon impersonating Apple's crash reporting service
Reported detail
Facts
AmnesiaStealer is a Rust-based macOS stealer deployed via counterfeit GitHub pages using ClickFix social engineering to trick users into running Terminal commands.
The malware operates in three stages: a shell script dropper, a Rust infostealer harvesting credentials and browser data, and a remote-control module providing live browser hijacking via Chrome DevTools Protocol.
It targets Chromium-based browsers and can exfiltrate cookies, login credentials, and session data while allowing operators to remotely control authenticated browser sessions at approximately 3 frames per second.
The malware uses social engineering to capture the macOS system password, then reuses it to unlock Keychain, access browser storage, and establish persistence through a fake Apple crash reporting service.
AmnesiaStealer's builder-driven configuration, version-specific OS bypasses, and sophisticated browser fingerprinting evasion techniques distinguish it from other macOS stealers like Atomic Stealer and MacSync.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Cataloged
Indicator3 indicators cataloged
Types: domain, tool.
Cataloged
IdentityAlias: TAG-22
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: Charcoal Typhoon
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: CHROMIUM
Reviewed identity mapping approved on this date.
Cataloged
IdentityAlias: ControlX
Reviewed identity mapping approved on this date.
Cataloged
IdentityTracking identifier: G1006
Reviewed identity mapping approved on this date.
First observed
CVECVE-2020-9771 linked to this actor
AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Earth LuscaCanonical Name
CHROMIUMAlias
Charcoal TyphoonAlias
ControlXAlias
TAG-22Alias
G1006Tracking Id
Loading CVEs, techniques, indicators, malware, victims, and activity...