Executive Summary
Sagerunex is a Windows‑only tool used by Lotus Blossom that steals credentials via LSASS dumps, browser data, and DCSync. It persists through registry run keys and scheduled tasks, then exfiltrates secrets over encrypted HTTP to C&C endpoints hosted on public web services. The malware’s modular design enables remote command execution, lateral movement, and opportunistic file exfiltration.
Enhanced Description
Sagerunex is a Windows‑only malware family that has been exclusively linked to the Lotus Blossom threat actor, with documented variants appearing as early as 2016. The code base implements a modular architecture that allows it to communicate with command and control (C&C) endpoints using non‑traditional web services such as popular cloud storage sites, public HTTP/HTTPS endpoints, or custom APIs, making detection by conventional botnet scanners challenging. Upon infection the loader registers persistence mechanisms—including registry run keys and scheduled tasks—and launches a stealthy back‑door component that exposes remote capabilities over HTTP. Once established, Sagerunex harvests credential data from a variety of sources: local user accounts, domain credentials via DCSync or LSASS dumping, browser stored passwords, and remote services such as Microsoft Office 365. The extracted secrets are then packaged and exfiltrated to the attacker’s servers using encrypted HTTP tunnels, sometimes embedding them in JSON payloads under otherwise benign URLs. In addition to credential theft, the malware provides a command execution shell that supports PowerShell scripts and Windows command‑line utilities, allowing adversaries to move laterally across network shares, upload malicious payloads, or pivot through RDP sessions. The campaign’s reliance on publicly available web services for C&C complicates attribution but also affords the operators a higher level of operational security. Because Sagerunex can masquerade as legitimate traffic, normal inbound firewall rules will often permit its outbound communications, underscoring the need for advanced behavioral analytics and URL reputation checks. Overall the malware’s modular design, credential‑theft focus, and use of encrypted web services place it on the same threat curve as other sophisticated APT groups such as Lotus Blossom.
Key Capabilities
Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016. Variations of Sagerunex leverage non-traditional command and control mechanisms such as various web services.(Citation: Symantec Bilbug 2022)(Citation: Cisco LotusBlossom 2025)