The Lotus Blossom hacker group, also known as Spring Dragon, Billbug, or Thrip, has been identified leveraging legitimate cloud services like Dropbox, Twitter, and Zimbra for command-and-control (C2) communications in their cyber espionage campaigns.
Cisco Talos researchers attribute these sophisticated operations to the group with high confidence, citing the use of a custom backdoor family called Sagerunex.
Active since at least 2012, Lotus Blossom continues to target sectors such as government, manufacturing, telecommunications, and media across regions including the Philippines, Vietnam, Hong Kong, and Taiwan.
The Sagerunex backdoor has evolved into multiple variants designed to evade detection and maintain persistence in compromised environments.
Earlier versions relied on traditional Virtual Private Servers (VPS) for C2 operations. However, recent campaigns exhibit a shift toward third-party cloud services.
By utilizing Dropbox APIs, Twitter tokens, and Zimbra webmail APIs as C2 tunnels, the group effectively blends malicious traffic with legitimate service usage, complicating detection efforts.
For example:
These techniques highlight the group’s adaptability in exploiting widely used platforms to bypass traditional security mechanisms.
Lotus Blossom employs advanced methods to maintain long-term access within targeted networks.
The Sagerunex backdoor is injected directly into memory and configured to run as a service through system registry modifications.
Commands such as “netstat,” “ipconfig,” and “tasklist” are executed for reconnaissance, gathering detailed information about user accounts, processes, and network configurations.
Additionally, the group uses tools like:
These tactics enable the group to operate undetected for extended periods while conducting espionage activities.
Cisco Talos’ analysis links these campaigns to Lotus Blossom based on consistent tactics, techniques, and procedures (TTPs), as well as victim profiles.
The Sagerunex backdoor family remains central to their operations. Despite developing distinct variants over time, core functionalities such as time-check logic for execution delays remain consistent across all versions.
The use of legitimate cloud services for malicious purposes underscores the challenges organizations face in distinguishing between benign and harmful activity.
This development calls for enhanced monitoring of cloud-based traffic and robust endpoint protection solutions to mitigate risks posed by advanced persistent threats like Lotus Blossom.
Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup -> Try for free
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and…
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel…
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious…
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked…
A long-running pay-per-install (PPI) operation that used YouTube gaming channels and SEO-poisoned software downloads to…