Also known as: UNC5454, APT28, Fancy Bear, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, STAC6451 was published, CL-STA-0048, was publicly disclosed, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, Asia
Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, the Middle East, and Southeast Asia. The actor exploits web application vulnerabilities, such as CVE-2025-55182, and employs techniques like SQL injection, DLL sideloading, and the deployment of custom backdoors like PULSEPACK and BypassBoss. Earth Lamia conducts reconnaissance, file operations, and credential theft, often utilizing tools like Cobalt Strike and VShell.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Earth Lamia, a China-nexus Advanced Persistent Threat (APT) group, has been actively targeting financial, logistics, and government sectors across Latin America, the Middle East, and Southeast Asia. The group primarily exploits web application vulnerabilities using techniques like SQL injection and DLL sideloading, deploying custom backdoors such as PULSEPACK and BypassBoss. Their operations often include reconnaissance, credential theft, and data exfiltration, leveraging tools like Cobalt Strike for lateral movement.
Goals & Targeting
Earth Lamia's strategic objectives appear to center around collecting sensitive information and establishing long-term access within targeted organizations. The group's focus on sectors like finance and logistics suggests an interest in economic gain or espionage to gather competitive intelligence. Their geographic targeting across multiple regions may reflect a broader geopolitical agenda, leveraging their China-based operations for global reach.
Enhanced Description
Earth Lamia is a sophisticated APT group known for its targeted attacks against critical sectors globally. They exploit web application vulnerabilities, such as CVE-2025-55182, using SQL injection and DLL sideloading techniques to gain initial access. The group deploys custom backdoors like PULSEPACK and BypassBoss to maintain persistence within compromised networks. Earth Lamia's operations extend across multiple regions, including Latin America, the Middle East, and Southeast Asia, focusing on industries with sensitive data. Their use of tools like Cobalt Strike and VShell indicates a high level of operational maturity, aligning with typical APT behavior for long-term access and data theft.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Earth Lamia's campaigns are characterized by prolonged access and data theft. They have been observed targeting financial institutions, suggesting a focus on high-value assets. The group's operational tempo involves initial infiltration through web vulnerabilities, followed by methodical lateral movement using Cobalt Strike. Notable past operations include multiple intrusions into Latin American financial services, highlighting their ability to sustain campaigns across geographies.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence is high in Earth Lamia's operational details based on available data, but gaps remain regarding the full scope of their activities and potential undiscovered tools. Further research could uncover additional Tactics, Techniques, and Procedures (TTPs) and IOCs.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
46
Tools
0
Campaigns
39
IOCs
0
Observed Data
14
Tactics