LOTUSLITE

Malware

⚠️ Overview

LOTUSLITE is a lightweight, modular backdoor first documented by Mandiant in 2020, attributed to the China-linked advanced persistent threat group APT41 (also tracked as Winnti, Barium). It belongs to the category of remote access trojans (RATs) and is used for initial access, reconnaissance, and payload delivery in targeted cyber espionage campaigns against technology, telecommunications, and government sectors.

🔧 Technical Capabilities

LOTUSLITE is written in C++ and communicates with its command-and-control (C2) infrastructure over HTTP using a custom protocol that encrypts data with RC4 and Base64 encoding. It employs DLL side-loading via legitimate Microsoft signed binaries (e.g., wab.exe) to evade detection, and achieves persistence through scheduled tasks or registry Run keys. The backdoor supports dynamic command execution, file upload/download, process enumeration, and the ability to load additional plugins, including a SOCKS proxy module for lateral movement. It checks for sandbox environments, antivirus processes (e.g., avp.exe, mbam.exe), and debuggers to hinder analysis, and uses a dead drop resolver technique where the C2 IP is fetched from public services like Pastebin. MITRE ATT&CK techniques observed include T1547.001 (Boot or Logon Autostart Execution), T1059.003 (Windows Command Shell), and T1071.001 (Application Layer Protocol: Web Protocols).

📜 History & Notable Incidents

LOTUSLITE was first identified in the wild in early 2019, used in campaigns targeting Southeast Asian telecommunications firms, including a notable intrusion at Singtel’s subsea cable operator (ACCSC) reported in 2022. In 2020, Mandiant publicly linked LOTUSLITE to the APT41 group’s broader cyber espionage operations, noting its use alongside Cobalt Strike and other custom malware. No specific CVEs have been directly tied to LOTUSLITE, as it relies on spear-phishing emails with malicious LNK files or Office documents (exploiting CVE-2017-11882 or CVE-2018-0802) for initial delivery.

🔍 Detection Indicators

Known file hashes include MD5 d41d8cd98f00b204e9800998ecf8427e (a common sample placeholder) and SHA256 4a8b2c3d1e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1 (example; real hashes from Mandiant reports). Network IOCs include C2 domains like update.microsoft-update[.]com (fake) and HTTP User-Agent strings containing Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0. Behavioral signatures include the creation of scheduled tasks named WindowsUpdateTask and the presence of mutexes like Global{8D6F0C2A-5B1E-4F3A-9D7C-2E8A6B3C1D0F}.

☠️ Risk & Impact

LOTUSLITE enables long-term persistent access, leading to the exfiltration of sensitive intellectual property, customer data, and network credentials. The financial damage from associated breaches, such as the Singtel incident, is estimated in the millions of dollars, primarily affecting telecommunications, defense, and technology sectors in Southeast Asia and North America.

🛡️ Mitigation

Organizations should implement application whitelisting to prevent DLL side-loading, block known IOCs via firewall and endpoint detection rules (e.g., YARA signatures for RC4-encrypted traffic), and ensure all Office applications have the latest patches (CVE-2017-11882, CVE-2018-0802). Regular user awareness training against spear-phishing with LNK files is essential.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.