logo

TrendLabs Security Intelligence BlogThe State of the ESILE/Lotus Blossom Campaign - TrendLabs Security Intelligence Blog

ID: 2de5a30e-d51a-4f6e-9a4f-bebf0ec35d9c

STIX ID: report--2de5a30e-d51a-4f6e-9a4f-bebf0ec35d9c

Threat Score

70/100

Uploaded: 2026-08-21

Published Date: 2016-10-31

Last Modified Date: 2016-10-31

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Trend Micro's TrendLabs analyzes the ESILE/Lotus Blossom targeted attack campaign, detailing its spear-phishing delivery, the SetElise dropper and EliseDLL loader, persistence via services and registry entries, and a distinctive C2 URL pattern tied to the infected host's MAC address, attributing the activity to a nation-state actor and noting historical usage dating back to 2007–2012.