APT
ATLAS
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
⌘K
▸
sign in
Atlas
Actors
147
Names
471
Sectors
40
Requirements
480
LOADING
Lotus Blossom (aka Lotus Blossom, Billbug) · APT Atlas
Actors
/
Nation-state / APT
/
Asia
Lotus Blossom
G0030
APT
CN · China
AKA
Billbug · Esile · DRAGONFISH · RAFFLES PANDA · Thrip
CrowdStrike
:
Spring Dragon
Mandiant
:
APT51
Microsoft
:
Raspberry Typhoon
MITRE
:
G0030
Secureworks
:
BRONZE ELGIN
Targets
8
Sectors
9
Threat types
1
GIRs covered
0/480
Active since
2007
Pin to atlas
Watch
Share
Export
Also tracked as
5 vendor names · 5 other aliases
Open Rosetta Stone
CrowdStrike
Spring Dragon
Mandiant
APT51
Microsoft
Raspberry Typhoon
MITRE
G0030
Secureworks
BRONZE ELGIN
UNATTRIBUTED ALIASES
Billbug
Esile
DRAGONFISH
RAFFLES PANDA
Thrip
Victimology
Geographic footprint · 8 countries
Region filter
Export
origin · China
targeted countries · 8
ASIA ·
7
Hong Kong
·
Indonesia
·
Macau
·
Malaysia
·
Philippines
·
Taiwan
·
Vietnam
AMERICAS ·
1
United States
Sectors targeted
9 of 40
Government
100 actors
Defense
72 actors
Aerospace
59 actors
Technology
60 actors
Telecom
72 actors
Energy / Utilities
59 actors
Education & Research
62 actors
Media & Journalism
49 actors
Industrials / Engineering
29 actors
Tactics, techniques, procedures
Threat types + MITRE ATT&CK mapping
THREAT TYPES
ESP · Espionage
MITRE ATT&CK · 18 techniques
Execution
· 2
T1047
Windows Management Instrumentation
T1059.001
PowerShell
Persistence
· 1
T1543.003
Windows Service
Discovery
· 7
T1012
Query Registry
T1016
System Network Configuration Discovery
Collection
· 2
T1560.001
Archive via Utility
T1560.003
Archive via Custom Method
Exfiltration
· 1
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
Command And Control
· 3
T1090.001
Internal Proxy
Defense Impairment
· 1
T1112
Modify Registry
Stealth
· 1
T1134
Access Token Manipulation
GIR coverage
0 / 480 requirements satisfied
Open matrix
No GIRs mapped yet for this actor.
Open data
Machine-readable exports of this profile
JSON · REST
Actor record
Full profile via the public v1 API
STIX 2.1
Intrusion-set bundle
Deterministic ids · techniques + targeted countries
ATT&CK NAVIGATOR
Technique layer
18 techniques · layer format 4.5
Related actors
By origin and actor type
APT31
nation-state
China · 6 targets · since 2013
APT8
nation-state
China · 5 targets · since —
APT24
nation-state
China · 3 targets · since 2008
APT27
nation-state
China · 23 targets · since 2010
APT44
nation-state
Russia · 25 targets · since 2009
APT21
nation-state
China · 5 targets · since 2010
T1018
Remote System Discovery
T1046
Network Service Discovery
T1049
System Network Connections Discovery
T1083
File and Directory Discovery
T1482
Domain Trust Discovery
T1090.003
Multi-hop Proxy
T1219.002
Remote Desktop Software