Lotus Blossom
MITRE ATT&CK: G0030 View on attack.mitre.org
Aliases: DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip, ST Group, BRONZE ELGIN, ATK1, Red Salamander, Lotus BLossom, Billbug, Lotus Blossom, APT30, LotusBlossom, LOTUS PANDA
- First seen
- 2009-01-01 00:00:00
- Origin
- CN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Last IoC activity
- 2026-07-19 10:45:03
- Profile updated
- 2026-07-07 12:31:12
Targeted industries: government-and-public-sector technology-and-telecommunications defense-and-aerospace
Targeted regions: country_code:cn country_code:hk country_code:vn country_code:ph country_code:np
Context
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
Detection coverage
- 11 YARA rules
- 333 Sigma rules
Malware & tools used
- System Network Configuration Discovery (attack-pattern)
- Windows Service (attack-pattern)
- Domain Account (attack-pattern)
- Local Data Staging (attack-pattern)
- Access Token Manipulation (attack-pattern)
- Local Account (attack-pattern)
- Internal Proxy (attack-pattern)
- Steal Web Session Cookie (attack-pattern)
- Modify Registry (attack-pattern)
- System Network Connections Discovery (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Domain Trust Discovery (attack-pattern)
- Internet Connection Discovery (attack-pattern)
- Multi-hop Proxy (attack-pattern)
- Tool (attack-pattern)
- Remote System Discovery (attack-pattern)
- File and Directory Discovery (attack-pattern)
- Archive via Custom Method (attack-pattern)
- Archive via Utility (attack-pattern)
- Network Service Discovery (attack-pattern)
- Query Registry (attack-pattern)
- certutil (malware)
- Emissary (malware)
- Impacket (malware)
- Hannotog (malware)
Related threat objects
- APT30 (threat-actor)
Reports & references
- Kaspersky — The Spring Dragon Apt (report)
- Kaspersky — 79067 (report)
- cfr.org — Lotus Blossom (report)
- Palo Alto Unit 42 — Operation Lotus Blossom (report)
- accenture.com — Accenture Security Elise Threat Analysis (report)
- Palo Alto Unit 42 — Attack On French Diplomat Linked To Operation Lotus Blossom (report)
- community.rsa.com — Lotus Blossom Continues Asean Targeting (report)
- accenture.com — Accenture Security Dragonfish Threat Analysis (report)
- MITRE ATT&CK — G0030 (report)
- secureworks.com — Bronze Elgin (report)
- pwc.com — Yir Cyber Threats Report Download (report)
- fortiguard.fortinet.com — 4879 (report)
- Broadcom/Symantec — Espionage Asia Governments Cert Authority (report)
- Microsoft — Rw1Afyw (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- Cisco Talos — Lotus Blossom Espionage Group (report)
- Kaspersky — 70726 (report)
- web.archive.org — Accenture Security Dragonfish Threat Analysis (report)
- paloaltonetworks.com — Unit42 Operation Lotus Blossom (report)
- security.com — Espionage Asia Governments Cert Authority (report)
External references
- mitre-attack — G0030
- DRAGONFISH
- Thrip
- Lotus Blossom
- RADIUM
- Raspberry Typhoon
- Spring Dragon
- Bilbug
- Accenture Dragonfish Jan 2018
- Spring Dragon Jun 2015
- Lotus Blossom Jun 2015
- Cisco LotusBlossom 2025
- Microsoft Threat Actor Naming July 2023
- Symantec Bilbug 2022
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy