Lotus Blossom Continues ASEAN Targeting
ID: a2be0a5d-1d0e-4cc2-aea8-49e75a96f61e
STIX ID: report--a2be0a5d-1d0e-4cc2-aea8-49e75a96f61e
Threat Score
88/100
Uploaded: 2026-08-15
Published Date: 2019-04-03
Last Modified Date: 2019-04-03
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Lotus Blossom ran a targeted malvertising campaign against ASEAN-related targets delivering an RTF decoy that exploited CVE-2017-11882 to drop the Elise backdoor (NavShExt.dll), which is injected into iexplore.exe to perform data collection and C2 to 103.236.150.14; the report provides process timelines, registry autorun persistence, network captures, code excerpts showing AES/Base64 cookie encoding for C2, and multiple file and hash indicators for detection.
