LOTUS PANDA
Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
LOTUS PANDA is a China-linked cyber espionage APT group targeting government and military entities in Southeast Asia.
LOTUS PANDA (aka Spring Dragon) is a China-linked nation-state cyber espionage group targeting government and military entities. They primarily focus on countries in Southeast Asia, including Japan, Philippines, Hong Kong, Indonesia, Taiwan, and Vietnam. Their TTPs involve execution via WMI, persistence through Windows Service, stealth with Access Token Manipulation, credential access by stealing Web Session Cookies, and C2 communication via Multi-hop Proxy, utilizing malware families like Elise, Emissary, Hannotog, and Sagerunex. Defenders should monitor for anomalous WMI usage, suspicious C2 traffic (especially multi-hop proxies), and the execution of offensive tools like Impacket and AdFind.
Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
Implement detection and monitoring for tools used to test security products.
Monitor Windows Management Instrumentation (WMI) events and detect suspicious WMI queries.
Monitor newly created Windows services and detect suspicious services.
Monitor process creation and token manipulation events to detect access token manipulation.
Monitor web browser activity to detect theft of web session cookies.
Monitor system and domain queries to detect gathering of network configuration and domain account information.
Monitor file system activity and archiving operations to detect data staging and archiving.
Monitor network traffic and proxy activity to detect internal proxy and multi-hop proxy usage.
Monitor registry changes and detect suspicious registry modification.
The group primarily targets government and military entities.
Every claim on this page is drawn from the cited source (MISP Galaxy, MITRE ATT&CK, ransomware.live) — no attribution is invented.