ATT&CKReferencesCisco LotusBlossom 2025

Cisco LotusBlossom 2025

Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software1

Campaigns0

None recorded.

Procedure examples31

TechniqueUsed byProcedure example
T1012
Query Registry
GroupLotus Blossom

Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service.

T1016
System Network Configuration Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts.

T1016
System Network Configuration Discovery
MalwareSagerunex

Sagerunex will gather system information such as MAC and IP addresses.

T1016.001
Internet Connection Discovery
GroupLotus Blossom

Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet.

T1027.002
Software Packing
MalwareSagerunex

Sagerunex has used VMProtect to pack and obscure itself.

T1041
Exfiltration Over C2 Channel
MalwareSagerunex

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1047
Windows Management Instrumentation
GroupLotus Blossom

Lotus Blossom has used WMI to enable lateral movement.

T1049
System Network Connections Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `netstat` to identify system network connections.

T1055.001
Dynamic-link Library Injection
MalwareSagerunex

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1074.001
Local Data Staging
GroupLotus Blossom

Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration.

T1074.001
Local Data Staging
MalwareSagerunex

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1082
System Information Discovery
MalwareSagerunex

Sagerunex gathers information from the infected system such as hostname.

T1083
File and Directory Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines.

T1087.001
Local Account
GroupLotus Blossom

Lotus Blossom has used commands such as `net` to profile local system users.

T1087.002
Domain Account
GroupLotus Blossom

Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries.

T1090
Proxy
MalwareSagerunex

Sagerunex uses several proxy configuration settings to ensure connectivity.

T1090.001
Internal Proxy
GroupLotus Blossom

Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments.

T1090.003
Multi-hop Proxy
GroupLotus Blossom

Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments.

T1102.002
Bidirectional Communication
MalwareSagerunex

Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants.

T1102.003
One-Way Communication
MalwareSagerunex

Sagerunex has used web services such as Twitter for command and control purposes.

T1106
Native API
MalwareSagerunex

Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic.

T1112
Modify Registry
GroupLotus Blossom

Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry.

T1134
Access Token Manipulation
GroupLotus Blossom

Lotus Blossom has retrieved process tokens for processes to adjust the privileges of the launch process or other items.

T1140
Deobfuscate/Decode Files or Information
MalwareSagerunex

Sagerunex uses a custom decryption routine to unpack itself during installation.

T1480
Execution Guardrails
MalwareSagerunex

Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory.

T1539
Steal Web Session Cookie
GroupLotus Blossom

Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome.

T1543.003
Windows Service
GroupLotus Blossom

Lotus Blossom has configured tools such as Sagerunex to run as Windows services.

T1560.001
Archive via Utility
GroupLotus Blossom

Lotus Blossom has used WinRAR for compressing data in RAR format.

T1560.001
Archive via Utility
MalwareSagerunex

Sagerunex has archived collected materials in RAR format.

T1560.003
Archive via Custom Method
GroupLotus Blossom

Lotus Blossom has used custom tools to compress and archive data on victim systems.

T1588.002
Tool
GroupLotus Blossom

Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.