logo

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

ID: b1fee9d0-01d8-5bfb-b244-841f6475885a

STIX ID: report--b1fee9d0-01d8-5bfb-b244-841f6475885a

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2025-02-27

Date Updated: 2026-04-22

Author: Aman Mishra

...
...

Lotus Blossom (aka Spring Dragon/Billbug/Thrip) is a long‑running cyber-espionage APT using the Sagerunex backdoor and evolving variants that abuse legitimate cloud services (Dropbox, Twitter, Zimbra) for covert command-and-control and data exfiltration; Cisco Talos attributes multiple active campaigns targeting government, manufacturing, telecommunications and media in the Philippines, Vietnam, Hong Kong and Taiwan, and documents techniques including memory-injected backdoors, registry persistence, credential theft, proxy/relay tools and encrypted archiving to maintain long-term access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.