Lotus Blossom — APT Profile
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip, G0076, ATK78
IntelFusions coverage (1)
- Satellite attacks went from TV pranks to wiper malware 2026-08-06 · Cyber Incidents
Tools & malware
- AdFind Network Reconnaissance
- certutil LOLBin
- Elise Backdoor
- Emissary Backdoor
- Hannotog Backdoor
- Impacket Network Toolkit
- NBTscan Network Reconnaissance
- Ping Network Reconnaissance
- Sagerunex Backdoor
Vendor research
- How Microsoft names threat actors Microsoft
- Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies Security Response Attack Investigation Team
- The Spring Dragon APT Spring Dragon
- Operation Lotus Blossom Lotus Blossom
- Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries Symantec
- Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools Cisco
- DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES Accenture