Description
Sagerunex is a malware family exclusively associated with the Lotus Blossom intrusion set, with variants existing since at least 2016. Its variations use non-traditional command and control mechanisms, including various web services.
Stats
- First seen
- May 2022
- Last seen
- September 2026
MITRE ATT&CK techniques
18 techniques across 6 tactics.
Associated groups
Alert name variants
| Alert Name |
|---|
| Win32.Backdoor.Sagerunex |
| Win64.Backdoor.Sagerunex |