China's 'Earth Lusca' Propagates Multiplatform Backdoor
ID: 5210037d-e839-52d4-b362-59c9389fe711
STIX ID: report--5210037d-e839-52d4-b362-59c9389fe711
Feed Name: Dark Reading
Date Published: 2024-09-05
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Trend Micro researchers reported a novel Golang-based backdoor named KTLVdoor used in an attack attributed to China-linked APT Earth Lusca; the malware (Windows and Linux) masquerades as system utilities, employs strong obfuscation and encrypted communications, and provides full remote-control capabilities. Analysts observed over 50 Alibaba-hosted C2 servers communicating with KTLVdoor variants, suggesting wider testing or shared infrastructure among Chinese-speaking threat actors; the report includes IOCs and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
