Sagerunex is a Windows espionage backdoor and remote access tool closely associated with the China-linked Lotus Blossom intrusion set, also tracked as Billbug, Thrip, Spring Dragon, Lotus Panda, Red Salamander, Bronze Elgin, and Raspberry Typhoon. It has been used for years as a signature malware family in long-running intelligence collection operations targeting government, defense, telecommunications, manufacturing, media, banking, energy, military, and digital certificate-related organizations, with a strong concentration on victims in Asia including the Philippines, Vietnam, Hong Kong, and Taiwan.
Sagerunex is designed for resilient post-compromise access and supports modular remote command execution, execution of programs and shell commands, loading DLLs and invoking exported functions, downloading additional payloads, and theft of local files for exfiltration. It gathers host information, stages collected material locally, and has been observed archiving data in RAR format before transmitting it over established command-and-control channels. Variants encrypt configuration, logs, and network traffic, and use HTTPS for command and control. Some samples are proxy-aware and can enumerate or discover proxy settings through multiple mechanisms, allowing the malware to maintain connectivity in enterprise environments. More recent variants have also used legitimate third-party services such as Dropbox, Twitter, and Zimbra as command-and-control tunnels, in addition to more traditional infrastructure.
Operationally, Sagerunex emphasizes stealth and persistence. It has been installed as a Windows service, including through service-related registry configuration, and has been described as capable of running in memory after DLL injection. Reported variants use token impersonation to inherit the context of the logged-in user, improving access to proxy settings, filesystem resources, and network egress while reducing conspicuous process creation. The malware also supports configurable operating time windows so activity can be limited to selected hours, helping it blend with normal user behavior. Additional evasion measures reported for the family include encrypted local state, timestamp manipulation, and code obfuscation.
Sagerunex has figured prominently in Lotus Blossom espionage campaigns involving broad network compromise, long dwell times, and follow-on use of dual-use tools for reconnaissance, lateral movement, and data theft. Its long-term exclusive association with that actor and its evolution into cloud- and service-backed command-and-control variants make it a defining component of Lotus Blossom tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Sagerunex backdoor is fairly resilient and implements multiple forms of communication with its command-and-control (C&C) server.
Main Features: Sagerunex is shipped with several features, including modifying its configuration, executing commands remotely, downloading further files, or sending files to the C2. This piece of malware therefore appears as an efficient backdoor for espionage purposes.
27 distinct techniques documented for this family, organized by ATT&CK tactic.
In all cases, HTTPS is used, with user agent equal to: Mozilla/5.0 (compatible; MSIE 7.0; Win32).
the sample will try all the following supported connection modes... HTTPS with configured proxy ... use proxy provided by WPAD ... Use proxy from ... Internet Settings\ProxyServer ... get proxy from \Mozilla\Firefox\profiles.ini
Cisco Talos’ findings, according to which Sagerunex also leverages legitimate services such as Dropbox, Twitter, and Zimbra for C2 purposes.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Primary modular backdoor framework for Lotus Blossom; commonly installed as a Windows service; newer variants use legitimate cloud/email services for C2 to increase stealth.
Backdoor family described as a defining toolset element for Lotus Blossom operations for nearly a decade.
Backdoor used by Lotus Panda/Lotus Blossom since at least 2016; updated variants used against government and other sectors in parts of Asia.
A long-running backdoor family associated with Lotus Blossom, used for persistent access and espionage across multiple variants over years.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.