Dark Web Profile: Lotus Blossom
ID: 2e570eae-8f36-54b9-8794-8461a56b5fbb
STIX ID: report--2e570eae-8f36-54b9-8794-8461a56b5fbb
Feed Name: SOCRadar Blog
**Lotus Blossom** is a Chinese state-sponsored APT active since at least 2009 that performs long-term, intelligence-driven espionage against government, military, telecommunications, maritime, and supply-chain targets worldwide; the report details its evolution from spear-phishing and watering holes to sophisticated supply-chain compromises (including the 2025–2026 Notepad++ trojanized updates), lists key malware families (Elise, Sagerunex, Chrysalis, Hannotog), enumerates exploited CVEs, outlines TTPs and notable campaigns, and provides mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
