Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.
Not cited by any technique.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1012 Query Registry |
GroupLotus Blossom | Lotus Blossom has run commands such as `reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters` to verify if installed implants are running as a service. |
| T1016 System Network Configuration Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `ipconfig` and `netstat` to gather network information on compromised hosts. |
| T1016 System Network Configuration Discovery |
MalwareSagerunex | Sagerunex will gather system information such as MAC and IP addresses. |
| T1016.001 Internet Connection Discovery |
GroupLotus Blossom | Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet. |
| T1027.002 Software Packing |
MalwareSagerunex | Sagerunex has used VMProtect to pack and obscure itself. |
| T1041 Exfiltration Over C2 Channel |
MalwareSagerunex | Sagerunex encrypts collected system data then exfiltrates via existing command and control channels. |
| T1047 Windows Management Instrumentation |
GroupLotus Blossom | Lotus Blossom has used WMI to enable lateral movement. |
| T1049 System Network Connections Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `netstat` to identify system network connections. |
| T1055.001 Dynamic-link Library Injection |
MalwareSagerunex | Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory. |
| T1074.001 Local Data Staging |
GroupLotus Blossom | Lotus Blossom has locally staged compressed and archived data for follow-on exfiltration. |
| T1074.001 Local Data Staging |
MalwareSagerunex | Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution. |
| T1082 System Information Discovery |
MalwareSagerunex | Sagerunex gathers information from the infected system such as hostname. |
| T1083 File and Directory Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines. |
| T1087.001 Local Account |
GroupLotus Blossom | Lotus Blossom has used commands such as `net` to profile local system users. |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1090 Proxy |
MalwareSagerunex | Sagerunex uses several proxy configuration settings to ensure connectivity. |
| T1090.001 Internal Proxy |
GroupLotus Blossom | Lotus Blossom has used publicly available tools such as the Venom proxy tool to proxy traffic out of victim environments. |
| T1090.003 Multi-hop Proxy |
GroupLotus Blossom | Lotus Blossom has used tools such as the publicly available HTran tool for proxying traffic in victim environments. |
| T1102.002 Bidirectional Communication |
MalwareSagerunex | Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants. |
| T1102.003 One-Way Communication |
MalwareSagerunex | Sagerunex has used web services such as Twitter for command and control purposes. |
| T1106 Native API |
MalwareSagerunex | Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic. |
| T1112 Modify Registry |
GroupLotus Blossom | Lotus Blossom has installed tools such as Sagerunex by writing them to the Windows registry. |
| T1134 Access Token Manipulation |
GroupLotus Blossom | Lotus Blossom has retrieved process tokens for processes to adjust the privileges of the launch process or other items. |
| T1140 Deobfuscate/Decode Files or Information |
MalwareSagerunex | Sagerunex uses a custom decryption routine to unpack itself during installation. |
| T1480 Execution Guardrails |
MalwareSagerunex | Sagerunex uses a "servicemain" function to verify its environment to ensure it can only be executed as a service, as well as the existence of a configuration file in a specified directory. |
| T1539 Steal Web Session Cookie |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools to steal cookies from browsers such as Chrome. |
| T1543.003 Windows Service |
GroupLotus Blossom | Lotus Blossom has configured tools such as Sagerunex to run as Windows services. |
| T1560.001 Archive via Utility |
GroupLotus Blossom | Lotus Blossom has used WinRAR for compressing data in RAR format. |
| T1560.001 Archive via Utility |
MalwareSagerunex | Sagerunex has archived collected materials in RAR format. |
| T1560.003 Archive via Custom Method |
GroupLotus Blossom | Lotus Blossom has used custom tools to compress and archive data on victim systems. |
| T1588.002 Tool |
GroupLotus Blossom | Lotus Blossom has used publicly-available tools such as a Python-based cookie stealer for Chrome browsers, Impacket, and the Venom proxy tool. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.