Billbug Expands Cyber-Espionage Campaign in Southeast Asia
ID: 65a3a0ba-2dda-5f7e-b9ff-89dc8e3a04d1
STIX ID: report--65a3a0ba-2dda-5f7e-b9ff-89dc8e3a04d1
Feed Name: Dark Reading
A China-linked espionage group tracked as Billbug (also called Lotus Panda/Lotus Blossom) has achieved significant success infecting government and critical private-sector organizations across Southeast Asia in late 2024 and early 2025. The group uses evolving backdoors (Sagerunex/Elise) and multiple variants, leverages legitimate but outdated security binaries to load malicious components, employs diverse C2 channels (including Dropbox, X, Zimbra), and deploys tools for credential and cookie theft plus SSH backdoors, indicating a focused, sophisticated regional espionage campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
