Loading the current evidence view. Navigation and account controls remain available.
Threat actors
Loading the current evidence view. Navigation and account controls remain available.
Also known as: DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip
21
techniques
9
software
10,655
corpus matches
profile
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
techniques
21 attributed · most-instrumented first
software
9 malware & tools attributed
Elise
S0081
Emissary
S0082
Ping
S0097
certutil
S0160
Impacket
S0357
AdFind
S0552
NBTscan
S0590
Sagerunex
S1210
Hannotog
S1211
read this carefully
10,655 corpus matches is not attribution
That count is indicators which exhibit techniques Lotus Blossom is known to use. Many unrelated operators use the same techniques. Treat it as a shared-technique signal for hunting, never as first-party attribution to this group.
indicators exhibiting these techniques
Top by severity: each resolves to its own verdict.
+9 more techniques
showing 30 of 10,655
known aliases
Vendors name the same group differently. Searching any alias reaches this profile.