Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

Hannotog

Hannotog is a custom backdoor/loader malware associated with the Billbug espionage group, also tracked as Lotus Blossom and Thrip. It was documented by Symantec in 2019 and was reused in later Billbug activity observed since at least March 2022 targeting a digital certificate authority and multiple government and defense organizations in Asia. Multiple files believed to be Hannotog loaders were found on victim machines.

Based on the provided content, Hannotog is frequently used as a loader that prepares victim systems by creating Windows services for persistence, modifying local firewall settings via netsh to open a listening UDP port, and deploying secondary payloads such as Sagerunex. It can create a new service for persistence, stop services, gather system information, execute cmd.exe commands, download files, and upload encrypted data for exfiltration. Hannotog uses non-standard listening ports for command and control, including UDP port 5900.

The malware has been used in espionage-focused intrusions attributed to Billbug/Lotus Blossom/Thrip against victims in Asian countries, including government, defense, and a certificate authority. In the observed campaigns, Hannotog was used alongside Sagerunex and dual-use tools such as AdFind, Certutil, Ping, Tracert, Route, NBTscan, Winmail, and WinRAR.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Lotus Blossom

In activity documented by Symantec in 2019, we detailed how the group was using a backdoor known as Hannotog (Backdoor.Hannotog) and another backdoor known as Sagerunex (Backdoor.Sagerunex). Both these tools were also seen in this more recent activity. Multiple files that are believed to be loaders for the Hannotog backdoor were spotted on victim machines.

MITRE ATT&CK

Techniques & procedures

16 distinct techniques documented for this family, organized by ATT&CK tactic.

Execution

4 techniques
T1047Windows Management InstrumentationEvidence1

“Tools such as WMI, PsExec, and PowerShell are used to move laterally.”

T1059.001PowerShellEvidence2

The tools that were reportedly used by Billbug APT are the following: ... PowerShell

T1059.003Windows Command ShellEvidence4

Can execute cmd.exe /c %s command to gather system information

T1569.002Service ExecutionEvidence1

“Tools such as WMI, PsExec, and PowerShell are used to move laterally.” / “relied heavily on legitimate administrative tools such as PsExec and PowerShell…”

Persistence

1 technique
T1543.003Windows ServiceEvidence5

Can create a service for persistence Can also stop services

Privilege Escalation

1 technique
T1543.003Windows ServiceEvidence5

Can create a service for persistence Can also stop services

Credential Access

1 technique
T1003OS Credential DumpingEvidence1

The tools that were reportedly used by Billbug APT are the following: ... Mimikatz

Discovery

1 technique
T1018Remote System DiscoveryEvidence1

“Active Directory reconnaissance with AdFind…”

Lateral Movement

1 technique
T1021.002SMB/Windows Admin SharesEvidence1

The tools that were reportedly used by Billbug APT are the following: ... PsExec

Collection

1 technique
T1560Archive Collected DataEvidence1

The tools that were reportedly used by Billbug APT are the following: ... WinRAR

Command and Control

2 techniques
T1105Ingress Tool TransferEvidence3

A tool called Stowaway Proxy Tool was also downloaded to victim machines.

T1571Non-Standard PortEvidence2

Listens on port 5900

Exfiltration

3 techniques
T1020Automated ExfiltrationEvidence1
T1041Exfiltration Over C2 ChannelEvidence1

Can upload encrypted data

T1048Exfiltration Over Alternative ProtocolEvidence1

The tools that were reportedly used by Billbug APT are the following: ... WinSCP

Impact

1 technique
T1489Service StopEvidence1

Other

1 technique
T1562.004Disable or Modify System FirewallEvidence3

It executes netsh to update the firewall settings: netsh advfirewall firewall add rule ... netsh firewall add portopening UDP 5900 ... netsh firewall add allowedprogram ...

INDICATORS OF COMPROMISE

IOCs tracked for this family

23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Hashes
23 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.sha256●●●●●●●●●●●●View more in app4 years ago
hash.sha256●●●●●●●●●●●●View more in app4 years ago
hash.sha256●●●●●●●●●●●●View more in app4 years ago
hash.sha256●●●●●●●●●●●●View more in app4 years ago
hash.sha256●●●●●●●●●●●●View more in app4 years ago
hash.sha256●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching23

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping16

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.

Hannotog | Mallory