logo

LOTUS_PANDA__2015__unit42-operation-lotus-blossom.pdf

ID: d6af41da-7869-4b74-95ab-2821a5d59ec9

STIX ID: report--d6af41da-7869-4b74-95ab-2821a5d59ec9

Threat Score

90/100

Uploaded: 2026-08-15

Published Date: 2015-06-15

Last Modified Date: 2015-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Operation Lotus Blossom (Unit 42) describes a persistent APT campaign (2012–2015) that targeted military and government organizations in Vietnam, the Philippines, Taiwan, Hong Kong and Indonesia using spear-phishing and Office exploits (notably CVE-2012-0158) to deliver a custom backdoor called "Elise." The report provides in-depth technical analysis of three Elise variants (A, B, C), their persistence and C2 mechanisms, examples of decoy documents used for lures, and a comprehensive appendix of IOCs (SHA256s, domains, IPs) and campaign identifiers to support detection and remediation.