ChinaWidely attributedUnknownMITRE G0030

Lotus Blossom

Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
1.0
Low signal strength
Mentions2
Sources1
High conf.0
Last seenMay 2026
First observed
2017-05-31
Last active
Origin
China
Aliases
7
Techniques
21
Campaigns
0
China

Attribution signals

2 mentions · 1 source
#1suspectedmoderate
MalwareInfrastructure
recorded-future
May 2026

"Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor"

#2suspectedmoderate
MalwareInfrastructure
recorded-future
May 2026

"Lotus Blossom (suspected China state-sponsored) exploited CVE-2025-15556 to hijack Notepad++ update traffic between June and December 2025. The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis."

Hedge terms observed

suspected