Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Lotus Blossom

Also known as: DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip, Lotus Blossom, ST Group, sile, BRONZE ELGIN, ATK1, G0030, Red Salamander, Billbug, Lotus Panda, LotusBlossom, APT31, APT28, APT34, Earth Preta, Stately Taurus, tracked as, Bitterbug, Elise, Spring, is an, Eslie, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND

Description

Lotus Blossom, also known as Spring Dragon, Thrip, Bilbug, and many other aliases, emerged in the early 2000s and has consistently focused on state‑level targets across Southeast Asia and beyond. Public disclosures since 2009 highlight a pattern of exploiting supply chains (most notably the injection of malicious code into Notepad++), targeting digital certificate issuers to facilitate widespread trust exploitation, and conducting extensive reconnaissance against defense, telecommunications, financial services, and critical infrastructure sectors. The group's technical footprint is marked by persistent backdoors—Sagerunex for Windows persistence, Chrysalis as a remote access tool, and recent deployments of CrimsonRAT and AndroRAT for both desktop and mobile platforms. These implants are delivered via sophisticated social engineering techniques: spear‑phishing emails with malicious attachments or links, watering‑hole campaigns that compromise high‑profile websites, and in some cases compromised third‑party software updates. Beyond initial access, Lotus Blossom emphasizes stealth and persistence. It employs living‑off‑the‐land tactics such as PowerShell scripts, WMI queries (T1047), registry modification (T1112), and custom archiving scripts (T1560). Data exfiltration often uses the built‑in certutil utility (T1140) to encode payloads, and it orchestrates multi‑hop proxies (T1090.003) for command and control traffic. The actor’s operational tempo reflects a strategic focus on political and economic espionage. By targeting high‑profile ministries, defense contractors, telecommunication giants, and certificate authorities, Lotus Blossom seeks to gather intelligence that can be leveraged by its state sponsors for geopolitical advantage.

Goals & Targeting

Targeted Sectors

Defense
Government
Telecommunications
Financial services
Education
Healthcare
Non profit
Manufacturing
Energy
Media
Critical infrastructure
Aerospace
Think tank
Pharmaceutical
Aviation
Hospitality
Transportation
Retail
Chemical
Maritime
Legal services
Information technology
Mining
Gaming
Utilities
Nuclear
Entertainment
Oil gas
Construction

Targeted Countries / Regions

CN
US
RU
UA
IL
VN
TW
AE
JP
PK
IR
PL
BY
IN
SA
KR
GB
AU
TR
DE
LB
KZ
SG
IT
FR
MX
ES
CA
IQ
RO
NG
KP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 2 hours ago

Executive Summary

Lotus Blossom is a long‑standing Chinese Advanced Persistent Threat that has targeted Asian governments, telecoms and critical infrastructure since 2009. The group delivers custom backdoors such as Sagerunex, Chrysalis, CrimsonRAT (Windows) and AndroRAT (Android) through spear‑phishing, watering‑hole, and recent supply‑chain compromises (e.g., Notepad++). It remains highly sophisticated, leveraging living‑off‑the‑land tools like certutil for persistence and data exfiltration.

Goals & Targeting

Lotus Blossom’s overarching objective is political and economic espionage against Asian governments and allied entities. By infiltrating government agencies, defense contractors, telecom operators, and critical infrastructure, the group aims to exfiltrate strategic trade secrets, diplomatic communications, and technology blueprints. Its broad sectoral focus reflects an intent to harvest data that can influence regional security dynamics, technological innovation, and economic policy decision‑making for its sponsoring state.

Enhanced Description

Key Capabilities

  • Persistence via deployment of Sagerunex backdoor
  • Deployment of Chrysalis Backdoor
  • Spear‑phishing and social engineering campaigns
  • Watering‑hole attacks targeting high‑profile websites
  • Custom backdoors such as CrimsonRAT (Windows) and AndroRAT (Android)
  • Living‑off‑the‑land persistence techniques
  • Credential theft and espionage across multiple regions

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Credential Access
Discovery
Exfiltration
Defense Evasion
Privilege Escalation

ATT&CK Techniques

T1560
T1560.001
T1560.003
T1543.003
T1074.001
T1112
T1016
T1016.001
T1482
T1087.002
T1087.001
T1083
T1049
T1046
T1018
T1553
T1090.003
T1090.001
T1105
T1588.002
T1140
T1189
T1566
T1539
T1134
T1012

Software / Tooling

Sagerunex backdoor
Chrysalis Backdoor
CrimsonRAT
AndroRAT
certutil

Campaigns & Victims

Over the last decade, Lotus Blossom has maintained a consistent campaign against Asian state actors and critical industry stakeholders. The group’s operational tempo oscillates between rapid, high‑impact supply‑chain attacks—such as the notorious Notepad++ injection—and prolonged stealth operations that persist on compromised systems for months using backdoors like Sagerunex or Chrysalis. Victims span broad categories: defense ministries (including military branches), telecommunications operators, financial institutions, and even digital certificate authorities, underscoring a strategic aim to secure both intelligence and operational leverage. Notable operations include the 2015 ‘Operation Lotus Blossom’ that targeted government entities in Southeast Asia and recent reports of a supply‑chain compromise via a compromised installer for popular open‑source software.

IOC Patterns

  • Domain (malicious or spoofed)
  • File hash/filename
  • Email address or attachment used for spear‑phishing
  • Watering‑hole URL or hostname

Recommended Actions

  • Deploy advanced phishing detection and conduct regular user training against spear‑phishing attacks
  • Block known malicious URLs identified in watering‑hole campaigns using threat feeds and firewall rules
  • Implement endpoint detection and response (EDR) to detect, quarantine, and remediate backdoor binaries such as CrimsonRAT and AndroRAT
  • Monitor outbound traffic for encoded exfiltration via certutil or other utilities and establish anomaly thresholds
  • Patch critical vulnerabilities—including CVE‑2017‑11882—on a timely basis across all endpoints
  • Audit digital certificate issuers and monitor for anomalous signing activity to detect potential certificate authority compromise

Suggested Tags

Chinese state-sponsored APT
Persistent backdoors
Supply chain compromise
Spear phishing
Waterhole attack
Backdoor usage
CrimsonRAT
AndroRAT
Living-off-the-land techniques
Targeting India
Targeting Southeast Asia
Certificate authority compromise

Confidence Assessment

The data on Lotus Blossom is drawn from multiple reputable security reports and threat intelligence feeds, giving confidence in its classification as a state‑backed APT with a long history of targeting Asian entities. However, exact attribution details remain partially speculative due to the group’s extensive alias usage and overlapping capabilities with other Chinese actors (such as Dragonfish). Gaps persist around precise timelines for early activities pre‑2009, definitive evidence linking all identified tools to Lotus Blossom operations, and confirmation of the group's current activity level post‑2025. Further evidence collection would strengthen confidence in operational attribution and timeline clarity.

ATT&CK Techniques

Discovery
10 techniques

Software / Tooling

Observed Data

No observed data linked yet.

References

  1. Accenture Dragonfish Jan 2018 — Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.
  2. Spring Dragon Jun 2015 — Baumgartner, K.. (2015, June 17). The Spring Dragon APT. Retrieved February 15, 2016.
  3. Lotus Blossom Jun 2015 — Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.
  4. Cisco LotusBlossom 2025 — Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.
  5. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.
  6. Symantec Bilbug 2022 — Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.
  7. www.eset.com — Cited by web research for: APT28
  8. attack.mitre.org — Cited by web research for: T1560
  9. attack.mitre.org — Cited by web research for: Medusa
  10. www.paloaltonetworks.com — Cited by web research for: WildFire
  11. https://malpedia.caad.fkie.de — Cited by AI analysis.
  12. https://malpedia.caad.fkie.de/actor/lotus_panda — Cited by AI analysis.
  13. https://unit42.paloaltonetworks.com/operation-lotus-blossom/ — Cited by AI analysis.
  14. https://securelist.com/spring-dragon-updated-activity/79067/ — Cited by AI analysis.
  15. https://community.rsa.com/community/products/netwitness/blog/2018/02/13/lotus-blossom-continues-asean-targeting — Cited by AI analysis.
  16. https://www.accenture.com/t20180127T003755Z_w_/us-en/_acnmedia/PDF-46/Accenture-Security-Dragonfish-Threat-Analysis.pdf — Cited by AI analysis.
  17. https://www.symantec.com/blogs/threat-intelligence/thrip-hits-satellite-telecoms-defense-targets — Cited by AI analysis.
  18. https://www.symantec.com/blogs/threat-intelligence/thrip-apt-south-east-asia — Cited by AI analysis.
  19. https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/espionage-asia-govt-cert-authority — Cited by AI analysis.

Intel Summary

27

Techniques

55

Tools

1

Campaigns

17

IOCs

0

Observed Data

10

Tactics

Tags

APT
espionage
government
East Asia
Chinese state-sponsored APT
Persistent backdoors
Supply chain compromise
Spear phishing
Waterhole attack
Backdoor usage
CrimsonRAT
AndroRAT
Living-off-the-land techniques
Targeting India
Targeting Southeast Asia
Certificate authority compromise

Details

MITRE ID
G0030
Type
Unknown
Resource Level
Government
Primary Motivation
Espionage
Country of Origin
China (CN)
Confidence
90%
Added
Jul 22, 2026
STIX ID
intrusion-set--88b7dbc2-32d3-4e31-af2f-3fc24e1582d7
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.