Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 23:18:36 UTC APT group: Earth Lamia Names Earth Lamia (Trend Micro) Country China Motivation Information theft and espionage First seen 2023 Description (Trend Micro) Trend Research has identified Earth Lamia as an APT threat actor that exploits vulnerabilities in web applications to gain access to organizations, using various techniques for data exfiltration. Earth Lamia develops and customizes hacking tools to evade detection, such as PULSEPACK and BypassBoss. Earth Lamia has primarily targeted organizations in Brazil, India, and Southeast Asia since 2023. Initially focused on financial services, the group shifted to logistics and online retail, most recently focusing on IT companies, universities, and government organizations. Observed Sectors: Education, Financial, Government, IT, Retail, Shipping and Logistics. Countries: Brazil, India, Indonesia, Malaysia, Philippines, Thailand, Vietnam. Tools used BypassBoss, PULSEPACK. Information Last change to this card: 27 June 2025 Download this actor card in PDF or JSON format Source: https://apt.etda.or.th/cgi-bin/showcard.cgi?u=17ebc5f9-e718-4b31-b0ba-5abe21916af5 https://apt.etda.or.th/cgi-bin/showcard.cgi?u=17ebc5f9-e718-4b31-b0ba-5abe21916af5 Page 1 of 1