logo

Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools

ID: fd49a139-2227-5565-bfac-c02d29fb252b

STIX ID: report--fd49a139-2227-5565-bfac-c02d29fb252b

Feed Name: Cisco Talos

Threat Score
90/100

Date Published: 2025-02-27

Date Updated: 2026-04-27

Author: Joey Chen

...
...

Cisco Talos documents multi-year espionage operations by the Lotus Blossom APT that deploy the Sagerunex backdoor and supporting tooling to target government, telecommunications, manufacturing and media organizations across Southeast Asia; notable findings include multiple Sagerunex variants that use third‑party cloud services (Dropbox, Twitter, Zimbra) as C2 channels, detailed persistence techniques (service/registry install), auxiliary tools (cookie stealer, proxy/relay, archiver), and a list of campaign identifiers and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.