Not Simon<p>Three different organizations have noted overlaps between I-Soon and Earth Lusca (aka AQUATIC PANDA, BRONZE UNIVERSITY, CHROMIUM, Charcoal Typhoon, ControlX, FISHMONGER, Red Dev 10, RedHotel). </p><ul><li>Recorded Future, who tracks Earth Lusca as RedHotel, noted similarities between base of operations (Chengdu, Sichuan Province, China), malware used (ShadowPad and Winnti), and victimology. <a href="https://www.recordedfuture.com/redhotel-a-prolific-chinese-state-sponsored-group-operating-at-a-global-scale" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">recordedfuture.com/redhotel-a-</span><span class="invisible">prolific-chinese-state-sponsored-group-operating-at-a-global-scale</span></a></li><li><span class="h-card" translate="no"><a href="https://infosec.exchange/@nattothoughts" class="u-url mention" rel="nofollow noopener noreferrer" target="_blank">@<span>nattothoughts</span></a></span> reached a similar conclusion back in October 2023: <a href="https://nattothoughts.substack.com/p/i-soon-another-company-in-the-apt41" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">nattothoughts.substack.com/p/i</span><span class="invisible">-soon-another-company-in-the-apt41</span></a></li><li>in today's blog post, Trend Micro mentions the same three links: <a href="https://www.trendmicro.com/en_us/research/24/b/earth-lusca-uses-geopolitical-lure-to-target-taiwan.html" rel="nofollow noopener noreferrer" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">trendmicro.com/en_us/research/</span><span class="invisible">24/b/earth-lusca-uses-geopolitical-lure-to-target-taiwan.html</span></a></li></ul><p><a href="https://infosec.exchange/tags/iSoon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>iSoon</span></a> <a href="https://infosec.exchange/tags/China" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>China</span></a> <a href="https://infosec.exchange/tags/Anxun" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Anxun</span></a> <a href="https://infosec.exchange/tags/Leak" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Leak</span></a> <a href="https://infosec.exchange/tags/cyberespionage" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>cyberespionage</span></a> <a href="https://infosec.exchange/tags/APT" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT</span></a> <a href="https://infosec.exchange/tags/MustangPanda" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MustangPanda</span></a> <a href="https://infosec.exchange/tags/APT41" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>APT41</span></a> <a href="https://infosec.exchange/tags/Winnti" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>Winnti</span></a> <a href="https://infosec.exchange/tags/MPS" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>MPS</span></a> <a href="https://infosec.exchange/tags/RedHotel" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>RedHotel</span></a> <a href="https://infosec.exchange/tags/EarthLusca" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>EarthLusca</span></a> <a href="https://infosec.exchange/tags/CharcoalTyphoon" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>CharcoalTyphoon</span></a> <a href="https://infosec.exchange/tags/news" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>news</span></a></p>