Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools
The Lotus Blossom espionage group has been conducting cyber espionage campaigns targeting government, manufacturing, telecommunications, and media sectors in the Philippines, Vietnam, Hong Kong, and Taiwan. The group employs various versions of the Sagerunex backdoor, including new variants that use cloud services like Dropbox, Twitter, and Zimbra for command and control. Lotus Blossom utilizes multiple hacking tools and techniques to maintain long-term persistence in compromised networks. The attacks involve multi-stage operations, including reconnaissance, lateral movement, and data exfiltration. The group has been active since at least 2012 and continues to evolve its tactics and malware to evade detection.
Pulse ID: 67f038f22c3d7acc43c35cb7
Pulse Link: https://otx.alienvault.com/pulse/67f038f22c3d7acc43c35cb7
Pulse Author: AlienVault
Created: 2025-04-04 19:54:26
Be advised, this data is unverified and should be considered preliminary. Always do further verification.