Threat group.View on attack.mitre.org
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
| Technique | Procedure example |
|---|---|
| T1012 Query Registry |
Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service. |
| T1016 System Network Configuration Discovery |
Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016.001 Internet Connection Discovery |
Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| T1018 Remote System Discovery |
Lotus Blossom has used Ping to identify remote systems. |
| T1046 Network Service Discovery |
Lotus Blossom has used port scanners to enumerate services on remote hosts. |
| T1047 Windows Management Instrumentation |
Lotus Blossom has used WMI to enable lateral movement. |
| T1049 System Network Connections Discovery |
Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1074.001 Local Data Staging |
Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1083 File and Directory Discovery |
Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines. |
| T1087.001 Local Account |
Lotus Blossom has used commands such as `net` to profile local system users. |
| T1087.002 Domain Account |
Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1090.001 Internal Proxy |
Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.003 Multi-hop Proxy |
Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1112 Modify Registry |
Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1134 Access Token Manipulation |
Lotus Blossom has retrieved process tokens for processes to adjust the privileges of the launch process or other items. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.