logo

LOTUS_PANDA__2016__Emissary_Trojan_Changelog_Did_Operation_Lotus_Blossom_Cause_It_to_Evolve_-_Palo_Alto_Networks_Blog.pdf

ID: 1686a1b8-17b0-4812-b04e-b37fad5e6392

STIX ID: report--1686a1b8-17b0-4812-b04e-b37fad5e6392

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2016-10-31

Last Modified Date: 2016-10-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes the Emissary Trojan used in targeted cyber-espionage against Taiwan and Hong Kong, documenting its multi-year evolution (versions 1.0–5.4), capabilities (file exfiltration, remote shell, updating), delivery shifts (spear-phishing and compromised legitimate sites), and a comprehensive set of IOCs (file hashes, loader/installers, C2 URLs, campaign codes); the report highlights a surge of development activity after the Operation Lotus Blossom disclosure and notes operator TTP changes intended to evade detection.