Earth Lamia Strikes Again: Chinese Hackers Exploit Vulnerabilities Worldwide

Earth Lamia, a Chinese threat actor, has been targeting vulnerabilities in web applications worldwide since at least 2023. Known for exploiting SQL injection flaws, the group infiltrates sectors like finance and IT, using custom tools and backdoors. Remember, if you see “sysadmin123” pop up, you might want to call your IT department!

Pro Dashboard

Hot Take:

Watch out world, because Earth Lamia is here to make your life as complicated as a Rubik’s cube doused in hot sauce! These guys are juggling SQL injections and deploying webshells like they’re in a circus act, and it seems like no sector is safe from their digital acrobatics. So put on your cybersecurity helmets, because it’s going to be a bumpy ride!

Key Points:

  • Earth Lamia targets multiple sectors worldwide with a focus on specific industries over time.
  • The group exploits known vulnerabilities, especially in SQL injection, to compromise web applications.
  • Their toolkit includes deploying webshells, escalating privileges, and creating admin accounts.
  • They utilize BypassBoss, open-source tools, and custom loaders for executing malicious shellcode.
  • Trend Micro links Earth Lamia to other Chinese threat actors and espionage campaigns.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?