Netskope Threat Labs

LotusBlossom

ATP Sandbox Adv. HeuristicsNetskope IPS

Lotus Blossom is a threat group that has conducted long running espionage against governments and military organizations in Southeast Asia, often using the Sagerunex backdoor and attacks on exposed Microsoft Exchange servers.

First seen
March 2022
Last seen
September 2026
Lotusblossom
Alert Name
Win32.Trojan.LotusBlossom
Win64.Trojan.Lotusblossom
Win64.Trojan.LotusBlossom