CNChinaconfidence: 50G0030
LOTUS PANDALOTUS PANDA
Also known as: Spring Dragon · ST Group · DRAGONFISH · BRONZE ELGIN · ATK1 · G0030 · Red Salamander · Lotus BLossom · Billbug · Lotus Blossom · LOTUS PANDA
Origin
CN
Known aliases
11
Target sectors
2
Attribution
State-sponsored
Profile
LOTUS PANDA is a Chinese-attributed threat actor catalogued by MISP-Galaxy (MISP-Galaxy v341). The group is also tracked as Spring Dragon, ST Group, DRAGONFISH (and 7 more). Operational targeting focuses on the Military and Government sectors. Documented victim organisations include Japan, Philippines, Hong Kong and 3 other named victims. Original record: Lotus Blossom is a threat group that has targeted government and military organizations in Southeast Asia.
Aliases· 11
Spring DragonST GroupDRAGONFISHBRONZE ELGINATK1Red SalamanderLotus BLossomBillbugLotus BlossomLOTUS PANDA
Target sectors· 2
MilitaryGovernment
Known victims· 6
- Japan
- Philippines
- Hong Kong
- Indonesia
- Taiwan
- Vietnam
MITRE ATT&CK Group crosswalk
References
- https://securelist.com/blog/research/70726/the-spring-dragon-apt/
- https://securelist.com/spring-dragon-updated-activity/79067/
- https://www.cfr.org/interactive/cyber-operations/lotus-blossom
- https://unit42.paloaltonetworks.com/operation-lotus-blossom/
- https://www.accenture.com/t00010101T000000Z__w__/gb-en/_acnmedia/PDF-46/Accenture-Security-Elise-Threat-Analysis.pdf
- https://unit42.paloaltonetworks.com/attack-on-french-diplomat-linked-to-operation-lotus-blossom/
- https://community.rsa.com/community/products/netwitness/blog/2018/02/13/lotus-blossom-continues-asean-targeting
- https://www.accenture.com/t20180127T003755Z_w_/us-en/_acnmedia/PDF-46/Accenture-Security-Dragonfish-Threat-Analysis.pdf
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.