logo

Espionage Actor 'Lotus Blossom' Targets Southeast Asia

ID: 5e58ea66-b9ed-5482-912d-e9f278f6f09d

STIX ID: report--5e58ea66-b9ed-5482-912d-e9f278f6f09d

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2025-03-06

Date Updated: 2026-04-21

Author: Alexander Culafi, Senior News Writer, Dark Reading

...
...

Cisco Talos researchers detail Lotus Blossom, an espionage-focused APT active since 2012 targeting governments and industries around the South China Sea; the group deploys a DLL-injected RAT named Sagerunex (and related tools such as cookie stealers, privilege escalators and proxy relays), uses WMI for discovery, and has evolved variants that abuse Dropbox, Twitter and Zimbra APIs for covert C2 and exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.