LOTUS_PANDA__2015__unit42-operation-lotus-blossom.pdf
ID: d6af41da-7869-4b74-95ab-2821a5d59ec9
STIX ID: report--d6af41da-7869-4b74-95ab-2821a5d59ec9
Threat Score
90/100
Uploaded: 2026-08-15
Published Date: 2015-06-15
Last Modified Date: 2015-06-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Lotus Blossom (Unit 42) describes a persistent APT campaign (2012–2015) that targeted military and government organizations in Vietnam, the Philippines, Taiwan, Hong Kong and Indonesia using spear-phishing and Office exploits (notably CVE-2012-0158) to deliver a custom backdoor called "Elise." The report provides in-depth technical analysis of three Elise variants (A, B, C), their persistence and C2 mechanisms, examples of decoy documents used for lures, and a comprehensive appendix of IOCs (SHA256s, domains, IPs) and campaign identifiers to support detection and remediation.
