logo

Lotus Blossom Continues ASEAN Targeting

ID: a2be0a5d-1d0e-4cc2-aea8-49e75a96f61e

STIX ID: report--a2be0a5d-1d0e-4cc2-aea8-49e75a96f61e

Threat Score

88/100

Uploaded: 2026-08-15

Published Date: 2019-04-03

Last Modified Date: 2019-04-03

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Lotus Blossom ran a targeted malvertising campaign against ASEAN-related targets delivering an RTF decoy that exploited CVE-2017-11882 to drop the Elise backdoor (NavShExt.dll), which is injected into iexplore.exe to perform data collection and C2 to 103.236.150.14; the report provides process timelines, registry autorun persistence, network captures, code excerpts showing AES/Base64 cookie encoding for C2, and multiple file and hash indicators for detection.