logo

'Earth Lamia' Exploits Known SQL, RCE Bugs Across Asia

ID: dcedbb08-9c2e-598c-b3f9-a806bac31a6e

STIX ID: report--dcedbb08-9c2e-598c-b3f9-a806bac31a6e

Feed Name: Dark Reading

Threat Score
86/100

Date Published: 2025-05-30

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Earth Lamia, a China-linked threat actor active since 2023, is conducting an ongoing campaign exploiting unpatched, Internet-exposed servers across South and Southeast Asia (with activity noted in India and Brazil). The group uses SQL injection and multiple known RCE vulnerabilities — most recently the critical CVE-2025-31324 in SAP NetWeaver — to drop a modular backdoor called PulsePack that communicates with C2 servers and fetches additional plugins; attackers also use OSS tooling (lightly obfuscated) for privilege escalation, credential theft, and persistence, targeting governments, education, IT, logistics, retail, and financial organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.