Lotus Blossom
G00301 reportsaliases · Lotus Blossom · DRAGONFISH · Spring Dragon · RADIUM · Raspberry Typhoon · Bilbug · Thrip
1
Reports
8
Techniques
5
Tactics
2
Countries
50%
Hunt coverage
7
Aliases
Analyst assessment — key judgments
- Signature techniques: T1583.007 (Serverless), T1071.004 (DNS), T1204.002 (Malicious File).
- Primary targeting: CN, US.
- Currently dormant: 0 report(s) in last 30d vs 0 prior (+0%).
- Hunt coverage 50% of 8 observed techniques (4 gap(s)).
- Assessment confidence: medium (60).
Activity & trend
DormantLast 30d: 0 vs 0 prior (+0%)· first reported 2026-02-18 · last 2026-02-18
0
7d
0
30d
0
90d
1
All
0.0
Rpts/wk
Reporting timeline · 12 months
Movement — last 30 days
Dropped (90d+)
T1583.007T1071.004T1204.002T1543.003T1195T1195.002T1584.007AML.T0008.004Overview
Analyst triage
Intelligence summary
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.(Citation: Lotus Blossom Jun 2015)(Citation: Symantec Bilbug 2022)(Citation: Cisco LotusBlossom 2025)
Top co-occurring indicators
Aliases & naming
Targeting · countries
Targeting · named victims
ATT&CK technique matrix
Coverage vs hunt library:
—
Hunt-coverage gaps — prioritized
Top techniques by observation
- T1583.007 · Serverlessconf 601
- T1071.004 · DNSconf 601
- T1204.002 · Malicious Fileconf 601
- T1543.003 · Windows Serviceconf 601
- T1195 · Supply Chain Compromiseconf 601
- T1195.002 · Compromise Software Supply Chainconf 601
- T1584.007 · Serverlessconf 601
- AML.T0008.004 · Serverlessconf 601
Threat catalogue · engineering roadmap
Flagged detection-engineering queue
Uncovered techniques you flagged for hunt / detection build-out, aggregated across every actor you visit. Stored locally in your browser.
Infrastructure
IOC type mix
Tooling / malware families
Relationships
Activity
30-day mention timeline
Recent reporting
| Title | Source | Severity | Collected |
|---|