Lotus Blossom
Also reported as Spring Dragon, Thrip, DRAGONFISH, Billbug, Red Salamander and 14 other names. Linked to China by three sources.
Reports per quarter
Techniques seen in the last two years
- T1005 2 reports reports only
- T1041 2 reports reports only
- T1070.004 2 reports reports only
- T1007 1 report reports only
- T1020 1 report reports only
- T1027 1 report reports only
- T1027.007 1 report reports only
- T1036 1 report reports only
- T1036.008 1 report reports only
- T1039 1 report reports only
Show all 34 techniques Show fewer
- T1046 1 report in ATT&CK
- T1055 1 report reports only
- T1055.002 1 report reports only
- T1056.003 1 report reports only
- T1057 1 report reports only
- T1059.003 1 report reports only
- T1069.002 1 report reports only
- T1071.001 1 report reports only
- T1078 1 report reports only
- T1083 1 report in ATT&CK
- T1105 1 report reports only
- T1106 1 report reports only
- T1140 1 report reports only
- T1190 1 report reports only
- T1204.002 1 report reports only
- T1480.002 1 report reports only
- T1518.001 1 report reports only
- T1543.003 1 report in ATT&CK
- T1547.001 1 report reports only
- T1552.001 1 report reports only
- T1556.002 1 report reports only
- T1572 1 report reports only
- T1573 1 report reports only
- T1620 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-2883 KEV
- CVE-2010-3333 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2013-2729 KEV
- CVE-2013-5990
- CVE-2014-1761 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2015-3113 KEV
Show all 18 CVEs Show fewer
- CVE-2016-2776
- CVE-2016-6662
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2018-0802 KEV ransomware
- CVE-2025-22457 KEV ransomware
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
-
Lotus Blossom, Spring Dragon, Thrip
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Lotus Blossom, Spring Dragon, Thrip
Show all 50 reports Show fewer
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Billbug- State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries
-
iOS exploit chain deploys LightSpy feature-rich malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor iOS exploit chain deploys LightSpy feature-rich malware
-
iOS exploit chain deploys “LightSpy” feature-rich malware _ Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor iOS exploit chain deploys “LightSpy” feature-rich malware _ Securelist
-
The original link failed its last check. Original publisher Detailsfor mobile-malware-report.pdf
-
Thrip_ Ambitious Attacks Against High Level Targets Continue
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Thrip_ Ambitious Attacks Against High Level Targets Continue
-
Lotus Blossom Continues ASEAN Targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lotus Blossom Continues ASEAN Targeting
-
Latest Elise APT comes packed with Sandbox Evasions
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Latest Elise APT comes packed with Sandbox Evasions
-
Lotus Blossom Continues ASEAN Targeting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lotus Blossom Continues ASEAN Targeting
-
apt32-continues-asean-targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor apt32-continues-asean-targeting
-
Accenture-Security-Dragonfish-Threat-Analysis
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Accenture-Security-Dragonfish-Threat-Analysis
-
Spring Dragon – Updated Activity
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Spring Dragon – Updated Activity
-
Emissary Trojan Changelog_ Did Operation Lotus Blossom Cause It to Evolve_ - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Trojan Changelog_ Did Operation Lotus Blossom Cause It to Evolve_ - Palo Alto Networks Blog
-
Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve? - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve? - Palo Alto Networks Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor TrendLabs Security Intelligence BlogThe State of the ESILE/Lotus Blossom Campaign - TrendLabs Security Intelligence Blog
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve? - Palo Alto Networks BlogPalo Alto Networks Blog
-
ELISE: Security Through Obesity
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor ELISE: Security Through Obesity
-
Attack On French Diplomat Linked To Operation Lotus Blossom
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Attack On French Diplomat Linked To Operation Lotus Blossom
-
Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It To Evolve
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It To Evolve
-
Emissary Trojan Changelog- Did Operation Lotus Blossom Cause It to Evolve-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Emissary Trojan Changelog- Did Operation Lotus Blossom Cause It to Evolve-
-
Attack on French Diplomat Linked to Operation Lotus Blossom
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Attack on French Diplomat Linked to Operation Lotus Blossom
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Attack on French Diplomat Linked to Operation Lotus Blossom - Palo Alto Networks BlogPalo Alto Networks Blog
-
ELISE: Security Through Obesity - Cyber security updates
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ELISE: Security Through Obesity - Cyber security updates
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Spring Dragon APT
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Lotusblossom
-
Operation Lotus Blossom- A New Nation-State Cyberthreat-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Lotus Blossom- A New Nation-State Cyberthreat-
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Fidelis Threat Advisory #1012
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor PIVY-Appendix
Newest first. Details opens the report in Explore.