MITRE lists Thrip as an associated name for Lotus Blossom while retaining Thrip as a separate group record.
MediumLotus Blossom
G0030
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
Activity timeline
A dated ledger of actor-claimed victims, campaigns, indicators, identity mappings, relationships, and CVE links. Each date states what it measures. For extensive leak-site histories, victim entries are limited to the 100 most recent distinct listings.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Reviewed identity mapping approved on this date.
Identity and attribution
Exact names and tracking identifiers resolve to this canonical profile. Rebrands, affiliations, and overlapping clusters remain separate confidence-rated relationships.
Name map
Shared-name reviews
Every exact-name collision is reviewed. Same-actor decisions select a preferred profile while distinct and unresolved clusters remain separate.
MITRE lists Thrip as an associated name for Lotus Blossom while retaining Thrip as a separate group record. The catalog preserves both records and does not infer exact equivalence.
Loading CVEs, techniques, indicators, malware, victims, and activity...