logo

LOTUS_PANDA__2018__Accenture-Security-Dragonfish-Threat-Analysis.pdf

ID: cbdcb957-be90-4217-b8ce-743cf3b8e5fd

STIX ID: report--cbdcb957-be90-4217-b8ce-743cf3b8e5fd

Threat Score

78/100

Uploaded: 2026-08-15

Published Date: 2018-01-26

Last Modified Date: 2018-01-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary — This Accenture/iDefense intelligence report attributes a targeted cyber-espionage campaign to DRAGONFISH (Lotus Blossom) that uses a malicious Word document exploiting CVE-2017-11882 to drop an Elise-family DLL (NavShExt.dll) which injects into iexplore.exe, harvests host and network data, communicates with hardcoded C2 103.236.150.14, and persists via a Run registry key; the report includes detailed IoCs, TTPs, and mitigation/hunting recommendations.