Elise
MITRE ATT&CK: S0081 View on attack.mitre.org
Aliases: BKDR_ESILE, Page, EVILNEST, Elise
- First seen
- 2015-06-01 00:00:00
- Malware type
- backdoor, trojan
- Family
- Malware family
- Operating systems
- windows
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 15:43:51
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:th country_code:ph country_code:hk country_code:in
Context
Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.
Detection coverage
- 3 YARA rules
- 331 Sigma rules
Malware & tools used
- Match Legitimate Resource Name or Location (attack-pattern)
- Ingress Tool Transfer (attack-pattern)
- System Information Discovery (attack-pattern)
- Symmetric Cryptography (attack-pattern)
- System Service Discovery (attack-pattern)
- Windows Service (attack-pattern)
- System Network Configuration Discovery (attack-pattern)
- Rundll32 (attack-pattern)
- Process Discovery (attack-pattern)
- Encrypted/Encoded File (attack-pattern)
- Timestomp (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Local Data Staging (attack-pattern)
- File Deletion (attack-pattern)
- Web Protocols (attack-pattern)
- Standard Encoding (attack-pattern)
- Local Account (attack-pattern)
- Registry Run Keys / Startup Folder (attack-pattern)
- Dynamic-link Library Injection (attack-pattern)
Used by threat actors
- Lotus Blossom (threat-actor)
- Lumma Stealer Distribution via Spoofed Webpages (campaign)
Detection rules
- HARFANGLAB_Masepie_Campaign_Htmlstarter (yara-rule)
- SEKOIA_Apt_Apt28_Ukrnet_Phishing_Page (yara-rule)
- MALPEDIA_Win_Elise_Auto (yara-rule)
Reports & references
- Kaspersky — The Spring Dragon Apt (report)
- accenture.com — Accenture Security Dragonfish Threat Analysis (report)
- secureworks.com — Bronze Elgin (report)
- web.archive.org — Accenture Security Dragonfish Threat Analysis (report)
- paloaltonetworks.com — Unit42 Operation Lotus Blossom (report)
- web.archive.org — Globalthreatintelreport (report)
- github.com — Microsoft 365 Defender Hunting Queries (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Elise (report)
- joesecurity.org — 8409877569366580427 (report)
- Mandiant — Code Grafting To Unpack Malware In Emulation (report)
- accenture.com — Accenture Security Dragonfish Threat Analysis (report)
- researchcenter.paloaltonetworks.com — Emissary Trojan Changelog Did Operation Lotus Blossom Cause It To Evolve (report)
- Trend Micro — Rpt 1H 2014 Targeted Attack Trends In Asia Pacific (report)
- MITRE ATT&CK — S0081 (report)