Lotus Blossom — APT Profile
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.Also tracked as
DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip
Tools & malware
- AdFind Network Reconnaissance
- certutil LOLBin
- Elise Backdoor
- Emissary Backdoor
- Hannotog Backdoor
- Impacket Network Toolkit
- NBTscan Network Reconnaissance
- Ping Network Reconnaissance
- Sagerunex Backdoor
Vendor research
- How Microsoft names threat actors Microsoft
- Thrip: Espionage Group Hits Satellite, Telecoms, and Defense Companies Security Response Attack Investigation Team
- The Spring Dragon APT Spring Dragon
- Operation Lotus Blossom Lotus Blossom
- Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries Symantec
- Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools Cisco
- DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES Accenture