Researchers suspect the involvement of China and on groups of hackers sponsored by the Beijing government. The attacks carried out using a tested scheme starting with a phishing campaign that uses an infected Microsoft Office file to exploit a known vulnerability in Microsoft. The malware used is a variant of Gh0st RAT, a well know remote access Trojan, that enables to acquire the total control of the target allowing documents theft and cyber espionage. Researchers have also found that the group attacked also military research institutes and aerospace, energy, engineering, and shipping companies.”]
Source: https://securityaffairs.co/wordpress/3845/hacking/luckycat-japan-tibet-india.html

