Uptime Hamster: 10d 22h 44mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Earth Lamia

Earth Lamia

0 incidentes 0 paises 0 sectores apt CN Ultimo: -
Aliases: UNC5454
Ver en IntelTracker → APTTrail →
Earth Lamia is a suspected China-nexus advanced persistent threat (APT) group that emerged in 2023, primarily focused on cyber espionage and information theft. The group is known for its opportunistic yet adaptive approach to targeting, initially focusing on financial services before shifting to logistics, online retail, and most recently, IT companies, academic institutions, and government entities. A key distinguishing characteristic of Earth Lamia is its consistent reliance on exploiting known web application vulnerabilities, including SQL injection, as a primary method for initial access. The group develops and continuously refines a custom toolset, notably including the modular PULSEPACK backdoor and the privilege escalation tool BypassBoss, demonstrating an ongoing evolution in their operational capabilities. Earth Lamia is also tracked under the alias UNC5454.

Aliases del actor

UNC5454

Actores similares

apt-earthberberokaactor · 1apt-earthhundunactor · 1apt-earthwendigoactor · 1earthkapreactor · 1Earth Luscaapt · 1earth-berberokaactor · 1earth-kapreactor · 1Earth Wendigoapt · 0Earth Estriesapt · 0Earth Ammitapt · 0
Motivacion