🌐Lotus Blossom
🌐 Lotus Blossom is a tracked threat actor in the Clankerusecase corpus. ??-aligned. Primary motivation: State. We map 14 detection use cases to this actor across 21 MITRE ATT&CK techniques, with 0 threat-intel articles citing them.
14Use cases
0Articles
21Techniques
0IOCs
About this actor (MITRE)
[Lotus Blossom](https://attack.mitre.org/groups/G0030) is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, [Lotus Blossom](https://attack.mitre.org/groups/G0030) has also targeted entities such as digital certificate issuers.(Citation: Lotus Blossom Jun 2015)(Citation: Symantec Bilbug 2022)(Citation: Cisco LotusBlossom 2025)
Known aliases
Lotus BlossomDRAGONFISHSpring DragonRADIUMRaspberry TyphoonBilbugThrip
Top techniques
All other tracked techniques
T1018 · Remote System DiscoveryT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1049 · System Network Connections DiscoveryT1074.001 · Local Data StagingT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1087.002 · Domain AccountT1090.001 · Internal ProxyT1090.003 · Multi-hop ProxyT1112 · Modify RegistryT1134 · Access Token ManipulationT1482 · Domain Trust DiscoveryT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1560.001 · Archive via UtilityT1560.003 · Archive via Custom MethodT1588.002 · Tool