logo

Attack on French Diplomat Linked to Operation Lotus Blossom - Palo Alto Networks BlogPalo Alto Networks Blog

ID: dcd97e6d-3f78-48b0-b0c6-bde28269ea76

STIX ID: report--dcd97e6d-3f78-48b0-b0c6-bde28269ea76

Threat Score

75/100

Uploaded: 2026-08-15

Published Date: 2015-12-22

Last Modified Date: 2015-12-22

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 reports a November 2015 targeted spear-phishing incident against a French diplomat in Taipei where malicious Word attachments exploiting CVE-2014-6332 dropped the Emissary 5.3 backdoor (loader ishelp.dll, payload A08E81B411.DAT, config 75BD50EC.DAT). The analysis details the exploit modifications, VBScript extraction method, Emissary configuration and command set, C2 domains/IPs (ustar5.PassAs.us, dnt5b.myfw.us, 203.124.14.229, appletree.onthenetas.com), related hashes and TTP overlap with Operation Lotus Blossom, and assesses the activity as likely nation-state espionage targeting diplomatic and regional intelligence.