Friday, May 9, 2025
Homecyber securityLotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

Lotus Blossom Hacker Group Uses Dropbox, Twitter, and Zimbra for C2 Communications

Published on

SIEM as a Service

Follow Us on Google News

The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has been identified leveraging legitimate cloud services like Dropbox, Twitter, and Zimbra for command-and-control (C2) communications in their cyber espionage campaigns.

Cisco Talos researchers attribute these sophisticated operations to the group with high confidence, citing the use of a custom backdoor family called Sagerunex.

Active since at least 2012, Lotus Blossom continues to target sectors such as government, manufacturing, telecommunications, and media across regions including the Philippines, Vietnam, Hong Kong, and Taiwan.

- Advertisement - Google News
Lotus Blossom
Attack Chain

Multi-Variant Malware and Evasion Tactics

The Sagerunex backdoor has evolved into multiple variants designed to evade detection and maintain persistence in compromised environments.

Earlier versions relied on traditional Virtual Private Servers (VPS) for C2 operations. However, recent campaigns exhibit a shift toward third-party cloud services.

By utilizing Dropbox APIs, Twitter tokens, and Zimbra webmail APIs as C2 tunnels, the group effectively blends malicious traffic with legitimate service usage, complicating detection efforts.

For example:

  • Dropbox and Twitter Variants: These variants use APIs to establish C2 channels. After initial checks, they retrieve tokens to communicate with the C2 infrastructure. Collected data is encrypted and uploaded to Dropbox or transmitted via Twitter status updates.
  • Zimbra Variant: This version leverages Zimbra’s webmail service for both data exfiltration and command execution. Host information is encrypted into files attached to draft emails in compromised accounts.

These techniques highlight the group’s adaptability in exploiting widely used platforms to bypass traditional security mechanisms.

Persistence and Reconnaissance

Lotus Blossom employs advanced methods to maintain long-term access within targeted networks.

The Sagerunex backdoor is injected directly into memory and configured to run as a service through system registry modifications.

Lotus Blossom
Adjust privilege tool

Commands such as “netstat,” “ipconfig,” and “tasklist” are executed for reconnaissance, gathering detailed information about user accounts, processes, and network configurations.

Additionally, the group uses tools like:

  • Chrome Cookie Stealers: To harvest browser credentials.
  • Venom Proxy Tools: Customized for relaying connections.
  • Archiving Tools: For compressing and encrypting stolen files.
  • Port Relay Tools: To facilitate external communication from isolated systems.

These tactics enable the group to operate undetected for extended periods while conducting espionage activities.

Cisco Talos’ analysis links these campaigns to Lotus Blossom based on consistent tactics, techniques, and procedures (TTPs), as well as victim profiles.

The Sagerunex backdoor family remains central to their operations. Despite developing distinct variants over time, core functionalities such as time-check logic for execution delays remain consistent across all versions.

The use of legitimate cloud services for malicious purposes underscores the challenges organizations face in distinguishing between benign and harmful activity.

This development calls for enhanced monitoring of cloud-based traffic and robust endpoint protection solutions to mitigate risks posed by advanced persistent threats like Lotus Blossom.

Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free

Aman Mishra
Aman Mishra
Aman Mishra is a Security and privacy Reporter covering various data breach, cyber crime, malware, & vulnerability.

Latest articles

Critical Vulnerability in Ubiquiti UniFi Protect Camera Allows Remote Code Execution by Attackers

Critical security vulnerabilities in Ubiquiti’s UniFi Protect surveillance ecosystem-one rated the maximum severity score...

IXON VPN Client Vulnerability Allows Privilege Escalation for Attackers

A critical security vulnerability in IXON’s widely used VPN client has exposed Windows, Linux,...

Cisco IOS Software SISF Vulnerability Could Enable Attackers to Launch DoS Attacks

Cisco has released security updates addressing a critical vulnerability in the Switch Integrated Security...

Seamless AI Communication: Microsoft Azure Adopts Google’s A2A Protocol

Microsoft has announced its support for the Agent2Agent (A2A) protocol, an open standard developed...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Critical Vulnerability in Ubiquiti UniFi Protect Camera Allows Remote Code Execution by Attackers

Critical security vulnerabilities in Ubiquiti’s UniFi Protect surveillance ecosystem-one rated the maximum severity score...

IXON VPN Client Vulnerability Allows Privilege Escalation for Attackers

A critical security vulnerability in IXON’s widely used VPN client has exposed Windows, Linux,...

Cisco IOS Software SISF Vulnerability Could Enable Attackers to Launch DoS Attacks

Cisco has released security updates addressing a critical vulnerability in the Switch Integrated Security...