Emissary Trojan Changelog: Did Operation Lotus Blossom Cause It to Evolve? - Palo Alto Networks BlogPalo Alto Networks Blog
ID: e1524b06-2034-4492-ba9c-f6db9c146252
STIX ID: report--e1524b06-2034-4492-ba9c-f6db9c146252
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2016-05-16
Last Modified Date: 2016-05-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 analyzes the Emissary Trojan — a long-running espionage RAT used primarily against Taiwan and Hong Kong targets — documenting its development timeline, technical capabilities (file exfiltration, remote shell, DLL/service persistence, DLL injection), changes in delivery and infrastructure (compromised legitimate sites, DDNS), multiple version-specific changelog items, and extensive IOCs (hashes, C2 URLs, campaign codes) to support detection and tracking.
