TrendLabs Security Intelligence BlogThe State of the ESILE/Lotus Blossom Campaign - TrendLabs Security Intelligence Blog
ID: 2de5a30e-d51a-4f6e-9a4f-bebf0ec35d9c
STIX ID: report--2de5a30e-d51a-4f6e-9a4f-bebf0ec35d9c
Threat Score
70/100
Uploaded: 2026-08-21
Published Date: 2016-10-31
Last Modified Date: 2016-10-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's TrendLabs analyzes the ESILE/Lotus Blossom targeted attack campaign, detailing its spear-phishing delivery, the SetElise dropper and EliseDLL loader, persistence via services and registry entries, and a distinctive C2 URL pattern tied to the infected host's MAC address, attributing the activity to a nation-state actor and noting historical usage dating back to 2007–2012.
