THREAT_ACTOR · G0030
Lotus Blossom
Also known as: Lotus Blossom, DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip
Profile
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
MITRE ATT&CK ↗Techniques
21 ATT&CK techniques attributed to this actor.
T1012 Query RegistryT1016 System Network Configuration DiscoveryT1016.001 Internet Connection DiscoveryT1018 Remote System DiscoveryT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1049 System Network Connections DiscoveryT1074.001 Local Data StagingT1083 File and Directory DiscoveryT1087.001 Local AccountT1087.002 Domain AccountT1090.001 Internal ProxyT1090.003 Multi-hop ProxyT1112 Modify RegistryT1134 Access Token ManipulationT1482 Domain Trust DiscoveryT1539 Steal Web Session CookieT1543.003 Windows ServiceT1560.001 Archive via UtilityT1560.003 Archive via Custom MethodT1588.002 Tool
Software
9 malware/tools attributed to this actor.
EliseEmissaryPingcertutilImpacketAdFindNBTscanSagerunexHannotog
Related corpus activity
9,519 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to Lotus Blossom.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| cve-2023-44976 | cve | ransomware | 85 | 2 |
| cve-2026-1969 | cve | — | 85 | 1 |
| cve-2025-11837 | cve | — | 85 | 2 |
| cve-2026-3102 | cve | — | 85 | 3 |
| cve-2026-4368 | cve | ransomware | 85 | 1 |
| cve-2021-29441 | cve | — | 85 | 1 |
| cve-2025-0921 | cve | — | 85 | 2 |
| cve-2013-3307 | cve | — | 85 | 2 |
| cve-2025-34054 | cve | — | 85 | 4 |
| cve-2014-2321 | cve | — | 85 | 1 |
| cve-2020-22653 | cve | — | 85 | 2 |
| cve-2025-34117 | cve | — | 85 | 1 |
| cve-2017-18377 | cve | — | 85 | 1 |
| cve-2021-25646 | cve | — | 85 | 1 |
| cve-2025-23304 | cve | — | 85 | 2 |
| cve-2025-66478 | cve | — | 85 | 2 |
| cve-2026-22584 | cve | — | 85 | 2 |
| cve-2021-27076 | cve | — | 85 | 1 |
| cve-2025-68670 | cve | — | 85 | 2 |
| cve-2016-15047 | cve | — | 85 | 4 |
| cve-2024-1781 | cve | — | 85 | 1 |
| cve-2018-8007 | cve | — | 85 | 1 |
| cve-2021-4045 | cve | — | 85 | 1 |
| cve-2020-17456 | cve | — | 85 | 1 |
| cve-2020-22658 | cve | — | 85 | 2 |
| cve-2025-2492 | cve | — | 85 | 2 |
| cve-2022-47945 | cve | — | 85 | 1 |
| cve-2016-5681 | cve | — | 85 | 2 |
| cve-2013-7471 | cve | — | 85 | 1 |
| cve-2026-0740 | cve | — | 85 | 1 |
Showing the top 30 by severity of 9,519.