Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Malware Sagerunex

Sagerunex

TLP:CLEAR
Family

AI Analysis

· 1 day ago

Executive Summary

Sagerunex is a Windows‑only tool used by Lotus Blossom that steals credentials via LSASS dumps, browser data, and DCSync. It persists through registry run keys and scheduled tasks, then exfiltrates secrets over encrypted HTTP to C&C endpoints hosted on public web services. The malware’s modular design enables remote command execution, lateral movement, and opportunistic file exfiltration.

Enhanced Description

Sagerunex is a Windows‑only malware family that has been exclusively linked to the Lotus Blossom threat actor, with documented variants appearing as early as 2016. The code base implements a modular architecture that allows it to communicate with command and control (C&C) endpoints using non‑traditional web services such as popular cloud storage sites, public HTTP/HTTPS endpoints, or custom APIs, making detection by conventional botnet scanners challenging. Upon infection the loader registers persistence mechanisms—including registry run keys and scheduled tasks—and launches a stealthy back‑door component that exposes remote capabilities over HTTP. Once established, Sagerunex harvests credential data from a variety of sources: local user accounts, domain credentials via DCSync or LSASS dumping, browser stored passwords, and remote services such as Microsoft Office 365. The extracted secrets are then packaged and exfiltrated to the attacker’s servers using encrypted HTTP tunnels, sometimes embedding them in JSON payloads under otherwise benign URLs. In addition to credential theft, the malware provides a command execution shell that supports PowerShell scripts and Windows command‑line utilities, allowing adversaries to move laterally across network shares, upload malicious payloads, or pivot through RDP sessions. The campaign’s reliance on publicly available web services for C&C complicates attribution but also affords the operators a higher level of operational security. Because Sagerunex can masquerade as legitimate traffic, normal inbound firewall rules will often permit its outbound communications, underscoring the need for advanced behavioral analytics and URL reputation checks. Overall the malware’s modular design, credential‑theft focus, and use of encrypted web services place it on the same threat curve as other sophisticated APT groups such as Lotus Blossom.

Key Capabilities

  • Persist via registry run key and scheduled tasks
  • Establish stealthy C&C using public web services (HTTP/HTTPS)
  • Harvest credentials from LSASS, browsers, Office 365 accounts, and DCSync operations
  • Encrypt command & control traffic over HTTPS
  • Exfiltrate data as JSON payloads to attacker servers
  • Enable remote command execution via PowerShell & Windows CLI
  • Perform lateral movement across SMB/RDP shares

Description

Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016. Variations of Sagerunex leverage non-traditional command and control mechanisms such as various web services.(Citation: Symantec Bilbug 2022)(Citation: Cisco LotusBlossom 2025)

Details

Type
Malware
Platforms
Windows
Confidence
90%
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.