Hannotog — Malware Profile
Hannotog is a type of backdoor malware uniquely assoicated with Lotus Blossom operations since at least 2022.
MITRE ATT&CK techniques (7)
- T1020 Automated Exfiltration
- T1059.003 Windows Command Shell
- T1105 Ingress Tool Transfer
- T1489 Service Stop
- T1543.003 Windows Service
- T1571 Non-Standard Port
- T1686 Disable or Modify System Firewall