Earth Lamia, also tracked as UNC5454, is a China-nexus cyberespionage intrusion set tracked since 2023. It targets organizations in Brazil, India, and Southeast Asia, with broader activity across Latin America and the Middle East. Its targeting initially emphasized securities and brokerage firms, expanded to logistics and online retail during the second half of 2024, and subsequently included IT companies, universities, and government organizations. The group primarily gains access through SQL injection and exploitation of internet-facing applications. Its exploitation history includes vulnerabilities in Apache Struts2, GitLab, WordPress plugins, JetBrains TeamCity, CyberPanel, Craft CMS, and SAP NetWeaver. Earth Lamia also attempted to exploit React2Shell, CVE-2025-55182, within hours of its public disclosure in December 2025. After compromise, it deploys webshells, creates privileged accounts, steals credentials through LSASS memory dumping and extraction of Windows credential stores, and performs host and domain reconnaissance. It uses GodPotato, JuicyPotato, and the customized BypassBoss tool for privilege escalation, Fscan and Kscan for network discovery, and rakshasa and Stowaway for proxy tunneling and lateral movement. Scheduled tasks provide persistence, while event-log clearing, tool modification, encrypted loaders, and DLL sideloading support defense evasion. Earth Lamia deploys VShell, Cobalt Strike, Brute Ratel, and its modular .NET backdoor PULSEPACK. First observed in its attacks in August 2024, PULSEPACK loads server-delivered plugins in memory, collects host information, and encrypts communications and execution results. A version observed from March 2025 introduced WebSocket communications and moved core functionality into a server-delivered plugin. The actor frequently abuses legitimate executables, including security-vendor software, to sideload malicious components. No Earth Lamia ransomware deployment has been confirmed.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
50 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
16 malware families attributed to this actor across reporting.
11 additional families tracked in Mallory.
11 CVEs this actor has used in observed campaigns. 11 of them exploited in the wild.
AWS reported within hours of public disclosure, multiple China state-nexus threat groups, including Earth Lamia and Jackpot Panda, had been exploiting CVE-2025-55182 for initial access.
Amazon threat intelligence teams observed them simultaneously exploiting other recent N-day vulnerabilities, including CVE-2025-1338.
“More recently, Earth Lamia also exploited CVE-2025-31324 (SAP NetWeaver Visual Composer unauthenticated file upload vulnerability).” The attribution discussion connects exploitation campaigns to Cobalt Strike infrastructure and a VShell deployment involving the SNOWLIGHT stager.
The flaw has been tracked as CVE-2025-55182 for React and CVE-2025-66478 for Next.js, but Mitre... rejected the second CVE as duplicative.
Telemetry shows Earth Lamia exploited vulnerabilities on public-facing servers, including “CVE-2017-9805: Apache Struts2 remote code execution vulnerability.”
6 more CVEs tied to this actor tracked in Mallory.
65 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as one of several threat actors that previously exploited SAP NetWeaver CVE-2025-31324 as a zero day.
Earth Lamia is a China-linked group exploiting web application vulnerabilities for remote code execution and web shell deployment.
China-linked espionage group exploiting CVE-2025-55182 for initial access and persistence in cloud and technology sectors in APAC.
China-nexus intrusion set active since at least 2023, compromising internet-facing applications and SQL servers across multiple countries. Targeting shifted from securities and brokerage organizations to logistics and online retail, then IT companies, universities, and government organizations. It develops customized offensive tools and the modular PULSEPACK backdoor. The researchers observed database exfiltration but no ransomware deployment. Overlaps with STAC6451 and CL-STA-0048 are partial and do not establish that these clusters are identical.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.