Lotus Blossom is identified in the provided content as a cyber-espionage threat associated with advanced persistent threat activity and renewed operations. The content states that Lotus Blossom has retrieved process tokens in order to adjust the privileges of the launch process or other items, indicating Windows token manipulation for privilege adjustment. It is described as targeting organizations in cyber-espionage campaigns. The supporting content does not provide additional high-confidence details on specific infection vectors, malware family capabilities beyond token-related privilege adjustment, targeted industries, or concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
CTI Roundup: Auto-Color Malware, Vulnerable Windows Driver, and Lotus Blossom | Tanium
Malware associated with token theft/retrieval to adjust privileges of processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.