Sagerunex

S1210

Malware.View on attack.mitre.org

About this malware

Sagerunex is a malware family exclusively associated with Lotus Blossom operations, with variants existing since at least 2016. Variations of Sagerunex leverage non-traditional command and control mechanisms such as various web services.

Techniques used18

Procedure examples18

TechniqueProcedure example
T1016
System Network Configuration Discovery

Sagerunex will gather system information such as MAC and IP addresses.

T1027.002
Software Packing

Sagerunex has used VMProtect to pack and obscure itself.

T1027.013
Encrypted/Encoded File

Sagerunex can be passed a reference to an XOR-encrypted configuration file at runtime.

T1041
Exfiltration Over C2 Channel

Sagerunex encrypts collected system data then exfiltrates via existing command and control channels.

T1055.001
Dynamic-link Library Injection

Sagerunex is designed to be dynamic link library (DLL) injected into an infected endpoint and executed directly in memory.

T1057
Process Discovery

Sagerunex identifies the `explorer.exe` process on the executing system.

T1071.001
Web Protocols

Sagerunex communicates via HTTPS, at times using a hard-coded User Agent of `Mozilla/5.0 (compatible; MSIE 7.0; Win32)`.

T1074.001
Local Data Staging

Sagerunex gathers host information and stages it locally as a RAR file prior to exfiltration. Sagerunex stores logged data in an encrypted file located at `%TEMP%/TS_FB56.tmp` during execution.

T1082
System Information Discovery

Sagerunex gathers information from the infected system such as hostname.

T1090
Proxy

Sagerunex uses several proxy configuration settings to ensure connectivity.

T1102.002
Bidirectional Communication

Sagerunex has used virtual private servers (VPS) for command and control traffic as well as third-party cloud services in more recent variants.

T1102.003
One-Way Communication

Sagerunex has used web services such as Twitter for command and control purposes.

T1106
Native API

Sagerunex calls the `WaitForSingleObject` API function as part of time-check logic.

T1134
Access Token Manipulation

Sagerunex finds the `explorer.exe` process after execution and uses it to change the token of its executing thread.

T1140
Deobfuscate/Decode Files or Information

Sagerunex uses a custom decryption routine to unpack itself during installation.

View all 18 procedure examples

Groups that use it1

Campaigns0

None recorded.

References2

  1. Cisco LotusBlossom 2025 Open source
    Joey Chen, Cisco Talos. (2025, February 27). Lotus Blossom espionage group targets multiple industries with different versions of Sagerunex and hacking tools. Retrieved March 15, 2025.
  2. Symantec Bilbug 2022 Open source
    Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.