Espionage Actor 'Lotus Blossom' Targets Southeast Asia
ID: 5e58ea66-b9ed-5482-912d-e9f278f6f09d
STIX ID: report--5e58ea66-b9ed-5482-912d-e9f278f6f09d
Feed Name: Dark Reading
Date Published: 2025-03-06
Date Updated: 2026-04-21
Author: Alexander Culafi, Senior News Writer, Dark Reading
Cisco Talos researchers detail Lotus Blossom, an espionage-focused APT active since 2012 targeting governments and industries around the South China Sea; the group deploys a DLL-injected RAT named Sagerunex (and related tools such as cookie stealers, privilege escalators and proxy relays), uses WMI for discovery, and has evolved variants that abuse Dropbox, Twitter and Zimbra APIs for covert C2 and exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
