GistPadiGistPadiGistPadi
  • Blog
  • Gist & Entertainment
  • Movie Reviews
  • Weird & Bizarre
  • Movie Downloads
    • Nollywood
    • Hollywood
    • Bollywood
    • TV Series & Shows
    • Korean Drama
    • Chinese &Thai Drama – Tv Shows and Series
    • Anime Shows and Movies
Reading: Lotus Panda hits unnamed government with bespoke hacking tools and malware
Share
Notification Show More
Font ResizerAa
GistPadiGistPadi
Font ResizerAa
  • Gist & Entertainment
  • Weird & Bizarre
  • Movie Downloads
  • Movie Reviews
  • Gist & Entertainment
  • Weird & Bizarre
  • Movie Downloads
  • Movie Reviews
Have an existing account? Sign In
Follow US
  • Advertise
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
GistPadi > Blog > Tech & Money > Lotus Panda hits unnamed government with bespoke hacking tools and malware
Tech & Money

Lotus Panda hits unnamed government with bespoke hacking tools and malware

admin
Last updated: April 22, 2025 8:53 pm
admin 4 months ago
Share
Lotus Panda hits unnamed government with bespoke hacking tools and malware
SHARE

Join Our Telegram Channel

Latest tech news Best money-saving apps Financial advice for millennials Technology trends 2025 Cryptocurrency updates

Contents
Chinese cyber-spiesYou might also like
Latest tech news Best money-saving apps Financial advice for millennials Technology trends 2025 Cryptocurrency updates A hacker wearing a hoodie sitting at a computer, his face hidden.
(Image credit: Shutterstock / Who is Danny)

  • The group struck government, air control, and telco firms in Southeast Asia
  • Victims were not named
  • Lotus Panda used never-before-seen infostealers and loaders

Lotus Panda, a Chinese state-sponsored threat actor, managed to compromise multiple organizations in a number of Southeast-Asian countries, in a campaign that took place between mid-2024 and early 2025.

Cybersecurity researchers from the Symantec Threat Hunter Team said the organizations included government agencies, air traffic control organizations, telecom operators, and a construction company in one country, a news agency in another, and an air freight organization in another. The victim countries, or organizations, were not named.

In the attack, the group used never-before-seen malware, loaders, credential stealers, and reverse SSH tools.

Chinese cyber-spies

Lotus Panda allegedly abused legitimate executables from antivirus companies Trend Micro and Bitdefender, using them to sideload malicious DLL files which dropped and decrypted second-stage payloads. The threat actor also allegedly updated Sagerunex, a group-exclusive tool that can steal sensitive information and exfiltrate it, encrypted, to a third-party server. We don’t know how the group made the initial breach, though.

Other notable tools used in this campaign are infostealers ChromeKatz and CredentialKatz.

“The attackers deployed the publicly available Zrok peer-to-peer tool, using the sharing function of the tool in order to provide remote access to services that were exposed internally,” Symantec said. “Another legitimate tool used was called ‘datechanger.exe.’ It is capable of changing timestamps for files, presumably to muddy the waters for incident analysts.

Lotus Panda is a known state-sponsored group, sometimes reported as Billbug, Lotus Blossom, Thrip, Spring Dragon, and Bronze Elgin. The group has allegedly been active since 2009, and is focused primarily on cyber-espionage. Its usual targets are government agencies, defense organizations, telcos and the media in Southeast Asia.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

There were also reports of Lotus Panda attacks in the United States and Australia, too, which could suggest that the group is looking to expand its reach.

Via The Hacker News

You might also like

  • UN warns massive billion-dollar fraud networks are on the rise in Southeast Asia
  • Take a look at our guide to the best authenticator app
  • We’ve rounded up the best password managers

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Join Our Telegram Channel

You Might Also Like

Empowering Nigeria’s Backbone: SeedFi and Winich Farms unlock access to credit for farmers 

MicroStrategy acquires 7,390 Bitcoin worth $764.9 million amid rising institutional adoption 

Ibadan airport to begin international flight operations by June 2026 

Lagos State seeks N3 trillion in public-private partnerships to combat coastal erosion 

A first-time fund manager is raising ₦100 billion to fund Africa’s data infrastructure gap

TAGGED:#CryptoNews#Fintech#GadgetReviews#InvestmentTips#TechUpdates
Share This Article
Facebook Twitter Whatsapp Whatsapp LinkedIn Telegram Threads Print
Previous Article Motorola Razr 60 Promo Pictures Leak Ahead of Announcement Motorola Razr 60 Promo Pictures Leak Ahead of Announcement
Next Article Pakistan grants first VPN licenses in a bid to regulate VPN usage in the country Pakistan grants first VPN licenses in a bid to regulate VPN usage in the country
Leave a comment

Leave a Reply Cancel reply

You must be logged in to post a comment.

All Spam Comment Will Be Deleted

Follow US

Find US on Social Medias
FacebookLike
TwitterFollow
YoutubeSubscribe
TelegramFollow
SnapchatSubscribe
Popular News
‘The Thursday Murder Club’ Review: Helen Mirren and Pierce Brosnan Make the Most of an Amiable Retirement Home Whodunit
Gist & Entertainment

‘The Thursday Murder Club’ Review: Helen Mirren and Pierce Brosnan Make the Most of an Amiable Retirement Home Whodunit

admin By admin 9 hours ago
Charli xcx, Doechii & Kneecap: The Best Moments From Glastonbury 2025 Day 2
Newark Mayor Ras Baraka arrested during ICE detention centre protest
Shohei Ohtani’s Wife: All About the MLB Player’s Marriage
Exmanželka Richarda Genzera ro už nevydržela. A tvrdě se pustila do Babiše!

Celebrity gossip, movie reviews, downloads & viral strange news. Gistpadi brings Hollywood, Nollywood, K-Drama,C-Drama,Thai-Drama,Anime & more to your screen.

  • Gist & Entertainment
  • Weird & Bizarre
  • Movie Reviews
  • Movie Downloads
  • Sports
  • Weird & Bizarre
  • Movie Reviews
  • Inspiration & Motivation
  • Blog
  • DMCA
  • Gistpadi Privacy Policy
  • Gistpadi Terms and Conditions

Find Us on Socials

© GistPadi Media Network. All Rights Reserved.
  • Blog
  • Gistpadi Terms and Conditions
  • Gistpadi Privacy Policy
adbanner
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist