🇨🇳

Earth Lamia

APT Group Information theft and espionage 12 zero-day CVEs ETDA ✓

Also Known As 1 names

UNC5454

Target Countries 7

Countries highlighted in red

Brazil Indonesia India Malaysia Philippines Thailand Vietnam

Sectors Targeted

Retail Shipping and Logistics Government IT Financial Education

Details

Origin 🇨🇳 CN
Last Updated 31 May 2025

MITRE ATT&CK 61

T1001 - Data Obfuscation T1003 - OS Credential Dumping T1021 - Remote Services T1027 - Obfuscated Files or Information T1036 - Masquerading T1036.004 - Masquerade Task or Service T1046 - Network Service Scanning T1049 - System Network Connections Discovery T1053 - Scheduled Task/Job T1053.005 - Scheduled TaskJob Scheduled Task T1055 - Process Injection T1059 - Command and Scripting Interpreter T1059.001 - Command and Scripting Interpreter PowerShell T1059.003 - Command and Scripting Interpreter Windows Command Shell T1059.007 - JavaScript T1068 - Exploitation for Privilege Escalation T1070.004 - File Deletion T1071 - Application Layer Protocol T1078 - Valid Accounts T1078.003 - Local Accounts T1082 - System Information Discovery T1102 - Web Service T1104 - Multi-Stage Channels T1105 - Ingress Tool Transfer T1132.001 - Standard Encoding T1136.001 - Create Account Local Account T1140 - Deobfuscate/Decode Files or Information T1176 - Browser Extensions T1189 - Drive-by Compromise T1190 - Exploit Public-Facing Application T1204 - User Execution T1204.002 - Malicious File T1211 - Exploitation for Defense Evasion T1496 - Resource Hijacking T1497 - Virtualization/Sandbox Evasion T1497.003 - Time Based Evasion T1505 - Server Software Component T1505.003 - Server Software Component Web Shell T1543 - Create or Modify System Process T1547 - Boot or Logon Autostart Execution T1566 - Phishing T1566.001 - Spearphishing Attachment T1574 - Hijack Execution Flow T1574.001 - DLL Search Order Hijacking T1583.001 - Domains T1583.003 - Virtual Private Server T1587.001 - Develop Capabilities Malware T1588 - Obtain Capabilities T1588.002 - Tool T1590 - Gather Victim Network Information T1592 - Gather Victim Host Information T1595 - Active Scanning T1595.001 - Scanning IP Blocks T1595.002 - Active Scanning Vulnerability Scanning T1608.001 - Stage Capabilities Upload Malware T1608.002 - Stage Capabilities Tool TA0001 - Initial Access TA0002 - Execution TA0003 - Persistence TA0005 - Defense Evasion TA0011 - Command and Control