Hannotog

S1211

Malware.View on attack.mitre.org

About this malware

Hannotog is a type of backdoor malware uniquely assoicated with Lotus Blossom operations since at least 2022.

Techniques used7

Procedure examples7

TechniqueProcedure example
T1020
Automated Exfiltration

Hannotog can upload encyrpted data for exfiltration.

T1059.003
Windows Command Shell

Hannotog can execute various `cmd.exe /c %s` commands.

T1105
Ingress Tool Transfer

Hannotog can download additional files to the victim machine.

T1489
Service Stop

Hannotog can stop Windows services.

T1543.003
Windows Service

Hannotog creates a new service for persistence.

T1571
Non-Standard Port

Hannotog uses non-standard listening ports, such as UDP 5900, for command and control purposes.

T1686
Disable or Modify System Firewall

Hannotog can modify local firewall settings via `netsh` commands to open a listening UDP port.

Groups that use it1

Campaigns0

None recorded.

References1

  1. Symantec Bilbug 2022 Open source
    Symntec Threat Hunter Team. (2022, November 12). Billbug: State-sponsored Actor Targets Cert Authority, Government Agencies in Multiple Asian Countries. Retrieved March 15, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.