logo

China-linked Billbug hackers breached multiple entities in Southeast Asian country

ID: ebb9a4ec-b697-53af-a046-1cac38494d10

STIX ID: report--ebb9a4ec-b697-53af-a046-1cac38494d10

Feed Name: The Record from Recorded Future News

Threat Score
90/100

Date Published: 2025-04-22

Date Updated: 2026-05-01

...
...

Symantec attributes a prolonged espionage campaign (Aug 2024–Feb 2025) in a Southeast Asian country to the Chinese APT group Billbug (Lotus Panda/Lotus Blossom/Bronze Elgin); attackers breached multiple high-profile targets including a government ministry, air traffic control, a telecom operator and a construction firm using custom credential stealers, backdoors and legitimate tools (including timestomping), and researchers note links to prior operations such as a compromise of a digital certificate authority.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.