Also known as: DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip, Lotus Blossom, ST Group, sile, BRONZE ELGIN, ATK1, G0030, Red Salamander, Billbug, Lotus Panda, LotusBlossom, APT31, APT28, APT34, Earth Preta, Stately Taurus, tracked as, Bitterbug, Elise, Spring, is an, Eslie, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257, PUSHCHA, Storm-0257, TA445, False Hunter, APT-Q-12, HIDDEN COBRA, WannaCry, APT37, Reaper, APT35, TA453, PHOSPHORUS, MosesStaff, C5, Smoke Sandstorm, TA455, UNC1549, HEXANE, Storm-0133, Scarred Manticore, Storm-0861, Crimson Sandstorm, Imperial Kitten, TA456, Yellow Liderc, APT-C-35, SectorE02, Volt Typhoon, Vanguard Panda, BRONZE HIGHLAND
Lotus Blossom, also known as Spring Dragon, Thrip, Bilbug, and many other aliases, emerged in the early 2000s and has consistently focused on state‑level targets across Southeast Asia and beyond. Public disclosures since 2009 highlight a pattern of exploiting supply chains (most notably the injection of malicious code into Notepad++), targeting digital certificate issuers to facilitate widespread trust exploitation, and conducting extensive reconnaissance against defense, telecommunications, financial services, and critical infrastructure sectors. The group's technical footprint is marked by persistent backdoors—Sagerunex for Windows persistence, Chrysalis as a remote access tool, and recent deployments of CrimsonRAT and AndroRAT for both desktop and mobile platforms. These implants are delivered via sophisticated social engineering techniques: spear‑phishing emails with malicious attachments or links, watering‑hole campaigns that compromise high‑profile websites, and in some cases compromised third‑party software updates. Beyond initial access, Lotus Blossom emphasizes stealth and persistence. It employs living‑off‑the‐land tactics such as PowerShell scripts, WMI queries (T1047), registry modification (T1112), and custom archiving scripts (T1560). Data exfiltration often uses the built‑in certutil utility (T1140) to encode payloads, and it orchestrates multi‑hop proxies (T1090.003) for command and control traffic. The actor’s operational tempo reflects a strategic focus on political and economic espionage. By targeting high‑profile ministries, defense contractors, telecommunication giants, and certificate authorities, Lotus Blossom seeks to gather intelligence that can be leveraged by its state sponsors for geopolitical advantage.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Lotus Blossom is a long‑standing Chinese Advanced Persistent Threat that has targeted Asian governments, telecoms and critical infrastructure since 2009. The group delivers custom backdoors such as Sagerunex, Chrysalis, CrimsonRAT (Windows) and AndroRAT (Android) through spear‑phishing, watering‑hole, and recent supply‑chain compromises (e.g., Notepad++). It remains highly sophisticated, leveraging living‑off‑the‑land tools like certutil for persistence and data exfiltration.
Goals & Targeting
Lotus Blossom’s overarching objective is political and economic espionage against Asian governments and allied entities. By infiltrating government agencies, defense contractors, telecom operators, and critical infrastructure, the group aims to exfiltrate strategic trade secrets, diplomatic communications, and technology blueprints. Its broad sectoral focus reflects an intent to harvest data that can influence regional security dynamics, technological innovation, and economic policy decision‑making for its sponsoring state.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Over the last decade, Lotus Blossom has maintained a consistent campaign against Asian state actors and critical industry stakeholders. The group’s operational tempo oscillates between rapid, high‑impact supply‑chain attacks—such as the notorious Notepad++ injection—and prolonged stealth operations that persist on compromised systems for months using backdoors like Sagerunex or Chrysalis. Victims span broad categories: defense ministries (including military branches), telecommunications operators, financial institutions, and even digital certificate authorities, underscoring a strategic aim to secure both intelligence and operational leverage. Notable operations include the 2015 ‘Operation Lotus Blossom’ that targeted government entities in Southeast Asia and recent reports of a supply‑chain compromise via a compromised installer for popular open‑source software.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The data on Lotus Blossom is drawn from multiple reputable security reports and threat intelligence feeds, giving confidence in its classification as a state‑backed APT with a long history of targeting Asian entities. However, exact attribution details remain partially speculative due to the group’s extensive alias usage and overlapping capabilities with other Chinese actors (such as Dragonfish). Gaps persist around precise timelines for early activities pre‑2009, definitive evidence linking all identified tools to Lotus Blossom operations, and confirmation of the group's current activity level post‑2025. Further evidence collection would strengthen confidence in operational attribution and timeline clarity.
Operation Lotus Blossom
No observed data linked yet.
27
Techniques
55
Tools
1
Campaigns
17
IOCs
0
Observed Data
10
Tactics