Elise

MITRE ATT&CK: S0081 View on attack.mitre.org

Aliases: BKDR_ESILE, Page, EVILNEST, Elise

First seen
2015-06-01 00:00:00
Malware type
backdoor, trojan
Family
Malware family
Operating systems
windows
Last IoC activity
2026-07-19 10:45:03
Profile updated
2026-07-07 15:43:51

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:th country_code:ph country_code:hk country_code:in

Context

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.

Detection coverage

  • 3 YARA rules
  • 331 Sigma rules

Malware & tools used

  • Match Legitimate Resource Name or Location (attack-pattern)
  • Ingress Tool Transfer (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Symmetric Cryptography (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Windows Service (attack-pattern)
  • System Network Configuration Discovery (attack-pattern)
  • Rundll32 (attack-pattern)
  • Process Discovery (attack-pattern)
  • Encrypted/Encoded File (attack-pattern)
  • Timestomp (attack-pattern)
  • File and Directory Discovery (attack-pattern)
  • Local Data Staging (attack-pattern)
  • File Deletion (attack-pattern)
  • Web Protocols (attack-pattern)
  • Standard Encoding (attack-pattern)
  • Local Account (attack-pattern)
  • Registry Run Keys / Startup Folder (attack-pattern)
  • Dynamic-link Library Injection (attack-pattern)

Used by threat actors

  • Lotus Blossom (threat-actor)
  • Lumma Stealer Distribution via Spoofed Webpages (campaign)

Detection rules

  • HARFANGLAB_Masepie_Campaign_Htmlstarter (yara-rule)
  • SEKOIA_Apt_Apt28_Ukrnet_Phishing_Page (yara-rule)
  • MALPEDIA_Win_Elise_Auto (yara-rule)

Reports & references

  • Kaspersky — The Spring Dragon Apt (report)
  • accenture.com — Accenture Security Dragonfish Threat Analysis (report)
  • secureworks.com — Bronze Elgin (report)
  • web.archive.org — Accenture Security Dragonfish Threat Analysis (report)
  • paloaltonetworks.com — Unit42 Operation Lotus Blossom (report)
  • web.archive.org — Globalthreatintelreport (report)
  • github.com — Microsoft 365 Defender Hunting Queries (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Elise (report)
  • joesecurity.org — 8409877569366580427 (report)
  • Mandiant — Code Grafting To Unpack Malware In Emulation (report)
  • accenture.com — Accenture Security Dragonfish Threat Analysis (report)
  • researchcenter.paloaltonetworks.com — Emissary Trojan Changelog Did Operation Lotus Blossom Cause It To Evolve (report)
  • Trend Micro — Rpt 1H 2014 Targeted Attack Trends In Asia Pacific (report)
  • MITRE ATT&CK — S0081 (report)

External references