Palo Alto Networks Unit 42 reported that Operation Lotus Blossom actors used a conference invitation as a social-engineering lure to target victims in a likely espionage-focused campaign. The activity relied on a themed decoy document to entice recipients into opening malicious content, continuing the group's pattern of using tailored documents and trusted-looking communications to gain an initial foothold.
The report links the lure to the broader Operation Lotus Blossom intrusion set, a threat actor associated with targeted attacks against organizations in Asia. The use of a conference-themed invitation highlights the group's emphasis on believable, context-specific phishing material designed to deliver malware and support long-term access to victim environments.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Palo Alto Networks Unit 42 published a public security advisory reporting that Operation Lotus Blossom actors were using a conference invitation as a lure in their activity. The reference provides no additional dated milestones beyond the advisory itself.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.