Lotus Blossom has run commands such as reg query HKLM\SYSTEM\CurrentControlSet\Services\[service name]\Parameters to verify if installed implants are running as a service.4
group
Lotus Blossom G0030
- Created
- 31 May 2017
- Last modified
- 31 July 2026
- Aliases
- Lotus Blossom · DRAGONFISH · Spring Dragon · RADIUM · Raspberry Typhoon · Bilbug · Thrip
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0030
Lotus Blossom has used commands such as ipconfig and netstat to gather network information on compromised hosts.5
Lotus Blossom has performed checks to determine if a victim machine is able to access the Internet.6
Lotus Blossom has used Ping to identify remote systems.7
Lotus Blossom has used port scanners to enumerate services on remote hosts.8
Lotus Blossom has used WMI to enable lateral movement.9
Standing G0030
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
55th percentile · 55% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
59th percentile · 59% of 176 ATT&CK groups have this many tactics spanned or fewer.
81st percentile · 81% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
64th percentile · 64% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0030
600 distinct rules cover the 21 techniques recorded for this group. The 668 technique-to-rule mappings resolve to 600 distinct rules, because one rule can cover several techniques. 359 Sigma · 241 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org