LOTUS_PANDA__2016__Emissary_Trojan_Changelog_Did_Operation_Lotus_Blossom_Cause_It_to_Evolve_-_Palo_Alto_Networks_Blog.pdf
ID: 1686a1b8-17b0-4812-b04e-b37fad5e6392
STIX ID: report--1686a1b8-17b0-4812-b04e-b37fad5e6392
Threat Score
75/100
Uploaded: 2026-08-15
Published Date: 2016-10-31
Last Modified Date: 2016-10-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes the Emissary Trojan used in targeted cyber-espionage against Taiwan and Hong Kong, documenting its multi-year evolution (versions 1.0–5.4), capabilities (file exfiltration, remote shell, updating), delivery shifts (spear-phishing and compromised legitimate sites), and a comprehensive set of IOCs (file hashes, loader/installers, C2 URLs, campaign codes); the report highlights a surge of development activity after the Operation Lotus Blossom disclosure and notes operator TTP changes intended to evade detection.
