SYMBOLCOMMON_NAMEaka. SYNONYMS

LOTUS PANDA  (Back to overview)

aka: ATK1, BRONZE ELGIN, Billbug, DRAGONFISH, G0030, Lotus BLossom, Lotus Blossom, Red Salamander, ST Group, Spring Dragon

Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.


Associated Families
win.chrysalis win.elise win.sagerunex

References
2026-02-03 ⋅ Kaspersky Labs ⋅ Anton Kargin, Georgy Kucherin
The Notepad++ supply chain attack — unnoticed execution chains and new IoCs
Chrysalis Cobalt Strike
2026-02-02 ⋅ Rapid7 ⋅ Ivan Feigl
The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit
Chrysalis
2026-01-02 ⋅ Securite360.net ⋅ Muffin
The Intriguing Lotus: A Deep Dive into Sagerunex
Sagerunex
2022-11-15 ⋅ Symantec ⋅ Threat Hunter Team
Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries
Sagerunex
2022-11-15 ⋅ Symantec ⋅ Threat Hunter Team
Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries
Sagerunex LOTUS PANDA
2022-11-15 ⋅ Fortinet ⋅ Fortinet
APT Billbug Victimized Asian Certification Authority and Government Agencies
LOTUS PANDA
2022-04-28 ⋅ PWC ⋅ PWC UK
Cyber Threats 2021: A Year in Retrospect
BPFDoor APT15 APT31 APT41 APT9 BlackTech BRONZE EDGEWOOD DAGGER PANDA Earth Lusca HAFNIUM HAZY TIGER Inception Framework LOTUS PANDA QUILTED TIGER RedAlpha Red Dev 17 Red Menshen Red Nue VICEROY TIGER
2021-05-20 ⋅ Github (microsoft) ⋅ Microsoft
Microsoft 365 Defender Hunting Queries for hunting multiple threat actors' TTPs and malwares
STRRAT OceanLotus BabyShark Elise Revenge RAT WastedLocker Zebrocy
2020-04-07 ⋅ FireEye ⋅ Michael Bailey
Thinking Outside the Bochs: Code Grafting to Unpack Malware in Emulation
Elise
2020-01-01 ⋅ Secureworks ⋅ SecureWorks
BRONZE ELGIN
Elise LOTUS PANDA
2019-01-01 ⋅ Council on Foreign Relations ⋅ Cyber Operations Tracker
Lotus Blossom
LOTUS PANDA
2019-01-01 ⋅ MITRE ⋅ MITRE ATT&CK
Group description: Lotus Blossom
LOTUS PANDA
2018-02-20 ⋅ Joe Security's Blog ⋅ Joe Security
Latest Elise APT comes packed with Sandbox Evasions
Elise
2018-02-13 ⋅ RSA ⋅ Kevin Stear
Lotus Blossom Continues ASEAN Targeting
LOTUS PANDA
2018-01-27 ⋅ Accenture Security ⋅ Accenture Security, Bart Parys
LATEST CYBER ESPIONAGE MALWARE ATTACKS - DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES
Elise
2018-01-01 ⋅ Accenture Security ⋅ Gareth Russell, Joshua Ray, Kelly Bissell, Ryan LaSalle, Uwe Kissman
LATEST CYBER ESPIONAGE MALWARE ATTACKS
LOTUS PANDA
2018-01-01 ⋅ Accenture ⋅ Bart Parys, Joshua Ray
Dragonfish delivers New Form of Elise Malware targeting ASEAN Defence Ministers' Meeting and Associates
Elise LOTUS PANDA
2017-07-24 ⋅ Kaspersky Labs ⋅ Noushin Shabab
Spring Dragon – Updated Activity
LOTUS PANDA
2016-02-03 ⋅ Palo Alto Networks Unit 42 ⋅ Jen Miller-Osborn, Robert Falcone
Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve?
Elise
2015-12-18 ⋅ Palo Alto Networks Unit 42 ⋅ Jen Miller-Osborn, Robert Falcone
Attack on French Diplomat Linked to Operation Lotus Blossom
LOTUS PANDA
2015-06-17 ⋅ Kaspersky Labs ⋅ Kurt Baumgartner
The Spring Dragon APT
Elise LOTUS PANDA
2015-06-16 ⋅ Palo Alto Networks Unit 42 ⋅ Unit42
Operation Lotus Blossom: A New Nation-State Cyberthreat?
LOTUS PANDA
2015-02-06 ⋅ CrowdStrike ⋅ CrowdStrike
CrowdStrike Global Threat Intel Report 2014
BlackPOS CryptoLocker Derusbi Elise Enfal EvilGrab Gameover P2P HttpBrowser MedusaHTTP Mirage Naikon NetTraveler pirpi PlugX Poison Ivy Sakula RAT Sinowal sykipot taidoor
2014-01-01 ⋅ Trend Micro ⋅ UnknownUnknown
Targeted Attack Trends in Asia-Pacific
Elise

Credits: MISP Project