logo

Dark Web Profile: Lotus Blossom

ID: 2e570eae-8f36-54b9-8794-8461a56b5fbb

STIX ID: report--2e570eae-8f36-54b9-8794-8461a56b5fbb

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2026-02-20

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**Lotus Blossom** is a Chinese state-sponsored APT active since at least 2009 that performs long-term, intelligence-driven espionage against government, military, telecommunications, maritime, and supply-chain targets worldwide; the report details its evolution from spear-phishing and watering holes to sophisticated supply-chain compromises (including the 2025–2026 Notepad++ trojanized updates), lists key malware families (Elise, Sagerunex, Chrysalis, Hannotog), enumerates exploited CVEs, outlines TTPs and notable campaigns, and provides mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.