SPRING DRAGON
THRIP
BILLBUG
LOTUS PANDA
Threat IntelligenceAPTFebruary 9, 202615 min read

Lotus Blossom: Threat Intelligence Profile

Chinese APT targeting Southeast Asian government and military organizations with custom backdoors, leveraging diplomatic-themed lures and strategic watering hole attacks.

Scroll

Lotus Blossom / Spring Dragon (also known as Spring Dragon, Thrip, Billbug, Lotus Panda) is a state-sponsored advanced persistent threat group attributed to China, active since 2012. The group primarily targets ASEAN governments, military, telecom sectors. It is tracked by MITRE ATT&CK as G0030.

Overview & Attribution

Chinese APT targeting Southeast Asian government and military organizations with custom backdoors, leveraging diplomatic-themed lures and strategic watering hole attacks.

Threat Assessment

Lotus Blossom has been active since 2012, attributed to China. The group is known for targeting ASEAN governments, military, telecom using a combination of custom malware, living-off-the-land techniques, and sophisticated social engineering.

Arsenal & Tools

Lotus Blossom employs a diverse arsenal of custom and shared tooling:

Targeting & Operations

The group focuses on ASEAN governments, military, telecom sectors, with operations spanning multiple geographic regions. Their campaigns typically involve carefully crafted spearphishing, strategic watering holes, and exploitation of public-facing applications.

Operational Pattern

Lotus Blossom is characterized by persistent, long-term access operations. Once inside a target network, the group establishes multiple redundant persistence mechanisms and moves laterally to high-value systems before beginning data exfiltration.

MITRE ATT&CK Mapping

TacticTechniqueUsage
Initial AccessT1566.001 Phishing AttachmentDiplomatic-themed spearphishing
ExecutionT1203 Exploitation for Client ExecutionRTF/Office exploits
PersistenceT1547.001 Registry Run KeysRegistry-based persistence
Defense EvasionT1036 MasqueradingDisguised as legitimate software
CollectionT1005 Data from Local SystemIntelligence gathering
C2T1071.001 Web ProtocolsHTTP C2

Notable Campaigns

Lotus Blossom has been linked to multiple significant campaigns targeting ASEAN governments, military, telecom organizations. The group continuously evolves its tooling and infrastructure to evade detection while maintaining persistent access to compromised networks.

Detection & Defense

Defend Against Lotus Blossom

Mjolnir Security provides specialized capabilities to detect and respond to Lotus Blossom operations.

APT DetectionThreat HuntingIncident ResponseMDR ServicesThreat Intelligence
  • APT Threat Hunting Proactive hunting for Lotus Blossom TTPs, tooling artifacts, and infrastructure indicators within your environment.
  • Threat Intelligence Continuous monitoring of Lotus Blossom campaigns and infrastructure changes with actionable intelligence for your defense team.
  • 24/7 Incident Response Rapid containment and forensic investigation. Call +1 833 403 5875.
Written by: Mjolnir Security  |  Published: February 9, 2026