🇨🇳
Earth Lamia
APT Group
Information theft and espionage
12 zero-day CVEs
ETDA ✓
Also Known As 1 names
UNC5454
Target Countries 7
Countries highlighted in red
Brazil
Indonesia
India
Malaysia
Philippines
Thailand
Vietnam
Sectors Targeted
Retail
Shipping and Logistics
Government
IT
Financial
Education
Details
Origin
🇨🇳 CN
Last Updated
31 May 2025
MITRE ATT&CK 61
T1001 - Data Obfuscation
T1003 - OS Credential Dumping
T1021 - Remote Services
T1027 - Obfuscated Files or Information
T1036 - Masquerading
T1036.004 - Masquerade Task or Service
T1046 - Network Service Scanning
T1049 - System Network Connections Discovery
T1053 - Scheduled Task/Job
T1053.005 - Scheduled TaskJob Scheduled Task
T1055 - Process Injection
T1059 - Command and Scripting Interpreter
T1059.001 - Command and Scripting Interpreter PowerShell
T1059.003 - Command and Scripting Interpreter Windows Command Shell
T1059.007 - JavaScript
T1068 - Exploitation for Privilege Escalation
T1070.004 - File Deletion
T1071 - Application Layer Protocol
T1078 - Valid Accounts
T1078.003 - Local Accounts
T1082 - System Information Discovery
T1102 - Web Service
T1104 - Multi-Stage Channels
T1105 - Ingress Tool Transfer
T1132.001 - Standard Encoding
T1136.001 - Create Account Local Account
T1140 - Deobfuscate/Decode Files or Information
T1176 - Browser Extensions
T1189 - Drive-by Compromise
T1190 - Exploit Public-Facing Application
T1204 - User Execution
T1204.002 - Malicious File
T1211 - Exploitation for Defense Evasion
T1496 - Resource Hijacking
T1497 - Virtualization/Sandbox Evasion
T1497.003 - Time Based Evasion
T1505 - Server Software Component
T1505.003 - Server Software Component Web Shell
T1543 - Create or Modify System Process
T1547 - Boot or Logon Autostart Execution
T1566 - Phishing
T1566.001 - Spearphishing Attachment
T1574 - Hijack Execution Flow
T1574.001 - DLL Search Order Hijacking
T1583.001 - Domains
T1583.003 - Virtual Private Server
T1587.001 - Develop Capabilities Malware
T1588 - Obtain Capabilities
T1588.002 - Tool
T1590 - Gather Victim Network Information
T1592 - Gather Victim Host Information
T1595 - Active Scanning
T1595.001 - Scanning IP Blocks
T1595.002 - Active Scanning Vulnerability Scanning
T1608.001 - Stage Capabilities Upload Malware
T1608.002 - Stage Capabilities Tool
TA0001 - Initial Access
TA0002 - Execution
TA0003 - Persistence
TA0005 - Defense Evasion
TA0011 - Command and Control