LOTUSLITE is a threat actor associated with targeted malware campaigns against U.S. government entities. Reported activity links the actor to spear-phishing operations that deliver malware through DLL side-loading, using legitimate signed applications to load malicious libraries and evade endpoint defenses. This tradecraft has been associated with stealthy backdoor deployment, encrypted command-and-control communications, in-memory execution, system reconnaissance, hidden command-shell access, and exfiltration of command output. Observed techniques also include anti-analysis measures such as virtual-machine and debugger detection, indicating a disciplined intrusion set with espionage-oriented tradecraft rather than overtly financial operations. LOTUSLITE has been referenced in connection with campaigns using geopolitical lures involving the United States and Venezuela. Some reporting notes moderate-confidence similarities between related activity and Mustang Panda tradecraft, including loader-and-malicious-DLL separation and infrastructure patterns, but any direct equivalence between the two should be treated cautiously absent stronger corroboration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Attributed campaign targeting the U.S. government using spear-phishing lures and a DLL side-loading vector to deliver malware, leveraging geopolitical narratives as thematic decoys.
Referenced as the attributed actor behind a DLL side-loading campaign (per Acronis) targeting the U.S. government; mentioned as an example of the broader trend of using DLL side-loading for reliable execution in targeted spear-phishing operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.