Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Earth Lamia

Also known as: UNC5454, APT28, Fancy Bear, tracked as, Paper Werewolf, Rare Werewolf, Central Asia, DarkGaboon, Vengeful Wolf, Black Owl, Lifting Zmiy, Hoody Hyena, which targets Russian companies, FoxBlade, MDaemon, Zimbra, in addition to Roundcube, Lotus Blossom, Lotus Panda, February 2025, Parisite, Pioneer Kitten, UNC757, FruityArmor, Sofacy, UNK_RemoteRogue, STAC6451 was published, CL-STA-0048, was publicly disclosed, Rezet, Head Mare, Unicorn, LAUNDRY BEAR, Bronze Elgin, Asia

Description

Earth Lamia is a China-nexus APT that targets organizations across multiple sectors, including finance, logistics, and government, primarily in Latin America, the Middle East, and Southeast Asia. The actor exploits web application vulnerabilities, such as CVE-2025-55182, and employs techniques like SQL injection, DLL sideloading, and the deployment of custom backdoors like PULSEPACK and BypassBoss. Earth Lamia conducts reconnaissance, file operations, and credential theft, often utilizing tools like Cobalt Strike and VShell.

Goals & Targeting

Targeted Sectors

Financial services
Government
Transportation
Energy
Defense
Telecommunications
Education
Retail
Manufacturing
Critical infrastructure
Utilities
Construction
Healthcare
Media
Aerospace
Maritime
Nuclear
Non profit
Aviation
Oil gas

Targeted Countries / Regions

IN
BR
CN
RU
TW
KR
TR
UA
IL
AE
CA
US
IR
JP
VN
SA
AU
middle_east

AI Analysis

· 1 week ago

Executive Summary

Earth Lamia, a China-nexus Advanced Persistent Threat (APT) group, has been actively targeting financial, logistics, and government sectors across Latin America, the Middle East, and Southeast Asia. The group primarily exploits web application vulnerabilities using techniques like SQL injection and DLL sideloading, deploying custom backdoors such as PULSEPACK and BypassBoss. Their operations often include reconnaissance, credential theft, and data exfiltration, leveraging tools like Cobalt Strike for lateral movement.

Goals & Targeting

Earth Lamia's strategic objectives appear to center around collecting sensitive information and establishing long-term access within targeted organizations. The group's focus on sectors like finance and logistics suggests an interest in economic gain or espionage to gather competitive intelligence. Their geographic targeting across multiple regions may reflect a broader geopolitical agenda, leveraging their China-based operations for global reach.

Enhanced Description

Earth Lamia is a sophisticated APT group known for its targeted attacks against critical sectors globally. They exploit web application vulnerabilities, such as CVE-2025-55182, using SQL injection and DLL sideloading techniques to gain initial access. The group deploys custom backdoors like PULSEPACK and BypassBoss to maintain persistence within compromised networks. Earth Lamia's operations extend across multiple regions, including Latin America, the Middle East, and Southeast Asia, focusing on industries with sensitive data. Their use of tools like Cobalt Strike and VShell indicates a high level of operational maturity, aligning with typical APT behavior for long-term access and data theft.

Key Capabilities

  • Web application vulnerability exploitation (SQL injection)
  • DLL sideloading attacks
  • Custom backdoor deployment (PULSEPACK, BypassBoss)
  • Use of Cobalt Strike for lateral movement and credential dumping
  • VShell tool employment

MITRE ATT&CK Tactics

Exploitation
Credential Access
Lateral Movement
Defense Evasion

ATT&CK Techniques

T1067
T1504.002
T1203
T1099
T1078

Software / Tooling

Cobalt Strike
VShell
PULSEPACK
BypassBoss

Campaigns & Victims

Earth Lamia's campaigns are characterized by prolonged access and data theft. They have been observed targeting financial institutions, suggesting a focus on high-value assets. The group's operational tempo involves initial infiltration through web vulnerabilities, followed by methodical lateral movement using Cobalt Strike. Notable past operations include multiple intrusions into Latin American financial services, highlighting their ability to sustain campaigns across geographies.

IOC Patterns

  • Exploitation of CVE-2025-55182
  • SQL injection activity in web logs
  • DLL sideloading indicators (process injection)
  • PULSEPACK and BypassBoss signatures in network traffic
  • Cobalt Strike beacons or C2 communication

Recommended Actions

  • Patch all web application vulnerabilities promptly.
  • Implement monitoring for SQL injection attempts and unusual DLL activity.
  • Deploy Honeypots on public-facing assets to detect initial access.
  • [Consider] adopting multi-factor authentication (MFA) for critical systems.
  • Regularly update software frameworks and libraries to minimize attack vectors.

Suggested Tags

APT
China-nexus
Web Application Exploits
Finance Sector

Confidence Assessment

Confidence is high in Earth Lamia's operational details based on available data, but gaps remain regarding the full scope of their activities and potential undiscovered tools. Further research could uncover additional Tactics, Techniques, and Procedures (TTPs) and IOCs.

ATT&CK Techniques

Collection
1 technique
Exfiltration
1 technique
Lateral Movement
1 technique
Privilege Escalation
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 1 Filename 8 Domain 9 IPv4 Address 2

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT28
  2. www.trendmicro.com — Cited by web research for: STAC6451 was published
  3. cloud.google.com — Cited by web research for: was publicly disclosed
  4. fortiguard.fortinet.com — Cited by web research for: CVE-2024-56145
  5. fortiguard.fortinet.com — Cited by web research for: CVE-2021-44228
  6. apt.etda.or.th — Cited by web research for: Education

Intel Summary

40

Techniques

46

Tools

0

Campaigns

39

IOCs

0

Observed Data

14

Tactics

Tags

APT
Critical Infrastructure
Backdoor / C2
Data Exfiltration
Government Targeting
China-nexus
Web Application Exploits
Finance Sector

Details

Type
Unknown
Resource Level
Unknown
Primary Motivation
Financial gain
Country of Origin
C
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.