Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools
ID: fd49a139-2227-5565-bfac-c02d29fb252b
STIX ID: report--fd49a139-2227-5565-bfac-c02d29fb252b
Feed Name: Cisco Talos
Cisco Talos documents multi-year espionage operations by the Lotus Blossom APT that deploy the Sagerunex backdoor and supporting tooling to target government, telecommunications, manufacturing and media organizations across Southeast Asia; notable findings include multiple Sagerunex variants that use third‑party cloud services (Dropbox, Twitter, Zimbra) as C2 channels, detailed persistence techniques (service/registry install), auxiliary tools (cookie stealer, proxy/relay, archiver), and a list of campaign identifiers and IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
