Skip to main content

Threats Tagged 'earth lamia'

View all threats tagged with 'earth lamia'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: earth lamia

Threats Tagged 'earth lamia'

Click on any threat for detailed analysis and mitigation recommendations

Within hours of the public disclosure of CVE-2025-55182 (React2Shell) on December 3, 2025, Amazon threat intelligence teams observed active exploitation attempts by multiple China state-nexus threat groups, including Earth Lamia and Jackpot Panda. This critical vulnerability in React Server Components has a maximum Common Vulnerability Scoring System (CVSS) score of 10.0 and affects React versions 19.x and Next.js versions 15.x and 16.x when using App Router.

Join the discussion

Operation DRAGONCLONE is an advanced cyber espionage campaign targeting China Mobile Tietong and potentially European telecom organizations connected to Chinese infrastructure. It uses sophisticated malware loaders like VELETRIX and the VShell adversary simulation tool, delivered via malicious ZIP files exploiting DLL sideloading and anti-analysis techniques such as IPFuscation. The campaign is linked to China-nexus threat groups UNC5174 (Uteus) and Earth Lamia and employs tools including SuperShell, Cobalt Strike, and Asset Lighthouse System. Active since March 2025, it focuses on credential theft, network reconnaissance, and callback execution. Detection requires monitoring for specific malware behaviors, DLL sideloading, and network callbacks. Germany, France, and the UK are at heightened risk due to their telecom sectors and economic ties to China. The threat is assessed as high severity given its advanced evasion, espionage intent, and potential impact on critical telecom infrastructure.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: earth lamia
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses