Researchers linked the Operation Lotus Blossom espionage campaign to the long-running Emissary and Elise malware families, tracing Emissary samples back to 2009 and tying the activity to intrusions against organizations in Taiwan, Hong Kong, and at least one French diplomat. The targeting and lures focused on government, military, higher education, and high-tech entities, often using decoy documents in Traditional Chinese. Infrastructure overlap between Emissary and Elise, including shared command-and-control hosting, reinforced the connection between the malware families and the broader campaign.
Analysis showed Emissary evolving rapidly across versions 1.0 through 5.4, adding new persistence methods, configuration changes, DLL injection, service hijacking, redesigned command handling, and anti-detection techniques such as recompilation and junk-data padding. After public reporting on Lotus Blossom, the operators appeared to accelerate development and shifted delivery tactics to compromised legitimate Taiwanese websites, including the Democratic Progressive Party site. More recent Elise samples were delivered through malicious RTF documents exploiting CVE-2018-0802, then injected into Internet Explorer and used sandbox-evasion checks, proxy modification, host reconnaissance, file transfer, and remote command execution to sustain espionage operations.

TTPs, infrastructure, and targeting history in one profile.
16 events from the most recent confirmed update back to the earliest known activity.
According to the Joe Security content, Microsoft patched the Equation Editor vulnerability CVE-2017-11882 in November 2017.
The Joe Security analysis states that Embedi detected an exploit in Microsoft Office Equation Editor in November 2017, later identified as CVE-2017-11882.
Unit 42 published a December 2015 report on cyber-espionage attacks using the Emissary Trojan as a payload, linking the malware to broader espionage activity.
Between August and November 2015, the malware author rapidly produced Emissary versions 5.0, 5.1, 5.3, and 5.4, indicating accelerated iteration to adapt and evade detection.
An out-of-sequence Emissary version 3.0 sample compiled on June 25, 2015 introduced DLL injection into Internet Explorer and switched from GUID-based to numeric commands, appearing to be an early variant of version 5.0.
Emissary version 4.0 was created in March 2015, combining installation, loading, and functional code in a single file and supporting persistence via service hijacking or Run keys.
Emissary version 3.0 was released in December 2014, marking another documented stage in the malware's evolution.
An updated Emissary 2.0 sample compiled in October 2013 added the ability to run as a service, expanding its persistence and execution options.
Emissary version 2.0 was created in September 2011 as a significant rewrite, including changes such as new configuration storage and debug logging.
A follow-on Emissary version 1.1 sample was created in June 2009, showing continued early development of the malware family.
Researchers identified the earliest known Emissary Trojan sample as having been created in May 2009, indicating the malware family had been active earlier than previously documented for related tooling.
Joe Security published an analysis of a recent Elise malware sample delivered via a malicious RTF document that exploited CVE-2018-0802, injected code into Internet Explorer, and used multiple sandbox-evasion checks before executing.
The Joe Security content says a second Equation Editor exploit, CVE-2018-0802, was detected in late December and was used by the analyzed Elise sample instead of CVE-2017-11882.
Unit 42 published a detailed changelog analysis of the Emissary Trojan, tracing its development from 2009 through late 2015 and linking it to Operation Lotus Blossom and Elise infrastructure.
Palo Alto Networks published research linking an attack on a French diplomat to Operation Lotus Blossom.
Palo Alto Networks published research on Operation Lotus Blossom, publicly documenting the campaign and its tooling.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 103 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
joesecurity.org
Open sourceresearchcenter.paloaltonetworks.com
Open sourceunit42.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.