Lotus Panda

THREAT ACTOR PROFILE

Lotus Panda

Lotus Panda

Lotus Panda

Billbug

Lotus Panda is a China-aligned espionage group active for over a decade, targeting government, telecom, financial and critical-infrastructure organizations, mostly across Southeast Asia. In 2025 it ran a six-month supply-chain compromise of Notepad++ update infrastructure, selectively redirecting high-value targets to the previously undocumented Chrysalis backdoor.

China

Government / Critical infrastructure

First seen

2012

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

Lotus Panda, Lotus Blossom and Billbug

Lotus Panda is tracked under several vendor names tied to its long history. It maps to one entry among the China-aligned APTs we document, and its regional espionage focus overlaps with crews like BlackTech.

-

-

-

GROUP PROFILE

Long-running espionage and a supply-chain pivot

Lotus Panda is a China-aligned espionage actor with a long track record against Southeast Asian governments and strategic industries. Its campaigns favor stealth, custom backdoors and, increasingly, supply-chain compromise to reach selected targets.

Our record places its origin as China and ties it to espionage across government, telecom, financial and critical-infrastructure sectors. The 2025 Notepad++ campaign hit organizations in Vietnam, El Salvador, Australia and the Philippines.

The group abused an insecure update mechanism in an outdated WinGUp component, running an adversary-in-the-middle redirect to deliver a malicious NSIS installer and the Chrysalis backdoor.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

ATTACK LIFECYCLE

WinGUp update hijack into Chrysalis

The stages below come from Lotus Panda and Lotus Blossom activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

Chrysalis, Sagerunex and Elise

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Supply-chain access over software exploitation

Lotus Panda's recent intrusions in our records center on supply-chain compromise and an insecure update mechanism rather than on exploiting a consistent set of software vulnerabilities, so this profile does not list a confirmed exploited-CVE set tied to the group. Detection should focus on the WinGUp update hijack and the Chrysalis backdoor.

Lotus Panda

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

Lotus Panda

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

Lotus Panda

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Lotus Panda

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

The Notepad++ supply-chain espionage campaign

Recent reporting tracks the Chrysalis backdoor and the update-hijack chain.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

Lotus Panda

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

Lotus Panda

IOC set, full IP, host and hash history.