Sagerunex is a Windows espionage backdoor and remote access tool closely associated with the China-linked Lotus Blossom intrusion set, also tracked as Billbug, Thrip, Spring Dragon, Lotus Panda, Red Salamander, Bronze Elgin, and Raspberry Typhoon. It has been used for years as a signature malware family in long-running intelligence collection operations targeting government, defense, telecommunications, manufacturing, media, banking, energy, military, and digital certificate-related organizations, with a strong concentration on victims in Asia including the Philippines, Vietnam, Hong Kong, and Taiwan.
Sagerunex is designed for resilient post-compromise access and supports modular remote command execution, execution of programs and shell commands, loading DLLs and invoking exported functions, downloading additional payloads, and theft of local files for exfiltration. It gathers host information, stages collected material locally, and has been observed archiving data in RAR format before transmitting it over established command-and-control channels. Variants encrypt configuration, logs, and network traffic, and use HTTPS for command and control. Some samples are proxy-aware and can enumerate or discover proxy settings through multiple mechanisms, allowing the malware to maintain connectivity in enterprise environments. More recent variants have also used legitimate third-party services such as Dropbox, Twitter, and Zimbra as command-and-control tunnels, in addition to more traditional infrastructure.
Operationally, Sagerunex emphasizes stealth and persistence. It has been installed as a Windows service, including through service-related registry configuration, and has been described as capable of running in memory after DLL injection. Reported variants use token impersonation to inherit the context of the logged-in user, improving access to proxy settings, filesystem resources, and network egress while reducing conspicuous process creation. The malware also supports configurable operating time windows so activity can be limited to selected hours, helping it blend with normal user behavior. Additional evasion measures reported for the family include encrypted local state, timestamp manipulation, and code obfuscation.
Sagerunex has figured prominently in Lotus Blossom espionage campaigns involving broad network compromise, long dwell times, and follow-on use of dual-use tools for reconnaissance, lateral movement, and data theft. Its long-term exclusive association with that actor and its evolution into cloud- and service-backed command-and-control variants make it a defining component of Lotus Blossom tradecraft.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The Sagerunex backdoor is fairly resilient and implements multiple forms of communication with its command-and-control (C&C) server.
Main Features: Sagerunex is shipped with several features, including modifying its configuration, executing commands remotely, downloading further files, or sending files to the C2. This piece of malware therefore appears as an efficient backdoor for espionage purposes.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
Attackers used a sophisticated loader that leverages Microsoft Warbird, an undocumented internal Windows code-protection framework. This allowed them to execute malicious shellcode while masquerading as a legitimate, Microsoft-signed binary, effectively bypassing many security solutions.
Examples throughout the content include 'encrypted payloads decrypted and executed in memory,' 'encrypts its configuration file,' 'AES-encrypted resource,' 'RC4 encrypted embedded scripts,' and 'payload includes an encrypted main component.'
The sample stores configuration and state in the following file: %appdata%/microsoft/protect/windows/DMI%X.DAT
The config file modification date will always be in the year 2011 – the “file last edit” year is changed by the malware to 2011.
Sagerunex leverage Explorer token impersonation. It can then behave exactly like the logged-in user
The content repeatedly describes malware and threat actors decoding, decrypting, or deobfuscating payloads, strings, configuration data, commands, and C2 traffic prior to execution or use, e.g., 'APT28 macro uses the command certutil -decode to decode contents of a .txt file storing the base64 encoded payload' and 'Action RAT can use Base64 to decode actor-controlled C2 server communications.'
The content repeatedly describes malware and threat actors obtaining lists of running processes, using utilities such as tasklist, ps, WMI, Get-Process, CreateToolhelp32Snapshot, EnumProcesses, and similar APIs/commands to enumerate active processes on victim systems.
The content repeatedly describes malware and threat actors collecting host details such as OS version, hostname, architecture, CPU, memory, BIOS, domain, language, and other configuration data; e.g., "APT41 uses multiple built-in commands such as systeminfo and net config Workstation to enumerate victim system basic configuration information."
11: Steal a local file (gets a file name specified in the command payload).
The content repeatedly describes adversaries and malware storing collected data, command output, credentials, archives, or files in local temporary folders, working directories, hidden directories, registry locations, recycle bins, or specific files prior to exfiltration.
Multiple actors and tools are described as using 7-Zip/WinRAR/zip/tar/gzip/makecab/PowerShell Compress-Archive to compress (often password-protect/encrypt) collected data prior to exfiltration (e.g., “used 7zip to archive extracted data in preparation for exfiltration”, “created password-protected RAR archives prior to exfiltration”, “used built-in PowerShell capabilities (Compress-Archive cmdlet) to compress collected data”).
In all cases, HTTPS is used, with user agent equal to: Mozilla/5.0 (compatible; MSIE 7.0; Win32).
AuditCred can utilize proxy for communications... FunnyDream can identify and use configured proxies in a compromised network for C2 communication... Kapeka can identify system proxy settings via WinHttpGetIEProxyConfigForCurrentUser() during initialization and utilize these settings for subsequent command and control operations... PoshC2 contains modules that allow for use of proxies in command and control.
the sample will try all the following supported connection modes... HTTPS with configured proxy ... use proxy provided by WPAD ... Use proxy from ... Internet Settings\ProxyServer ... get proxy from \Mozilla\Firefox\profiles.ini
It initially attempts to connect using the system’s default WinHTTP configuration... If this attempt fails, it seems to fall back to multiple explicit proxy discovery mechanisms including WPAD, Internet Explorer, Firefox, auto-proxy, and preconfigured proxy settings.
Cisco Talos’ findings, according to which Sagerunex also leverages legitimate services such as Dropbox, Twitter, and Zimbra for C2 purposes.
A tool called Stowaway Proxy Tool was also downloaded to victim machines.
In all cases, HTTPS is used... The network packet is composed of two parts: the header and the payload. Both are encrypted separately.
Multiple malware families and intrusion sets are described as encrypting C2 traffic using SSL/TLS/HTTPS (e.g., "used HTTPS for command and control", "encrypts C2 communications with TLS", "uses SSL for encrypting C2 communications", "TLS-encrypted WebSocket Protocol (WSS) for C2").
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
31 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Primary modular backdoor framework for Lotus Blossom; commonly installed as a Windows service; newer variants use legitimate cloud/email services for C2 to increase stealth.
Backdoor family described as a defining toolset element for Lotus Blossom operations for nearly a decade.
Backdoor used by Lotus Panda/Lotus Blossom since at least 2016; updated variants used against government and other sectors in parts of Asia.
A long-running backdoor family associated with Lotus Blossom, used for persistent access and espionage across multiple variants over years.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.