Earth Lamia
0 incidentes
0 paises
0 sectores
apt CN Ultimo: -
Aliases: UNC5454
Earth Lamia is a suspected China-nexus advanced persistent threat (APT) group that emerged in 2023, primarily focused on cyber espionage and information theft. The group is known for its opportunistic yet adaptive approach to targeting, initially focusing on financial services before shifting to logistics, online retail, and most recently, IT companies, academic institutions, and government entities. A key distinguishing characteristic of Earth Lamia is its consistent reliance on exploiting known web application vulnerabilities, including SQL injection, as a primary method for initial access. The group develops and continuously refines a custom toolset, notably including the modular PULSEPACK backdoor and the privilege escalation tool BypassBoss, demonstrating an ongoing evolution in their operational capabilities. Earth Lamia is also tracked under the alias UNC5454.