Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve? - Palo Alto Networks Blog
ID: da83558f-deb4-419a-ad2b-199fd3d88ef9
STIX ID: report--da83558f-deb4-419a-ad2b-199fd3d88ef9
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2016-10-31
Last Modified Date: 2016-10-31
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes the Emissary Trojan (2009–2015), documenting its evolution across multiple versions, functionality (file exfiltration, remote shell, payload updates), targeting (Taiwan and Hong Kong government, military, academia, high-tech), TTP shifts after public disclosure of Operation Lotus Blossom (use of compromised legitimate domains, faster development cadence), and provides extensive IOCs (SHA256 hashes, C2 URLs, campaign codes) to track the campaign.
