Hannotog is a custom Windows backdoor associated with the Billbug espionage group, also tracked as Lotus Blossom and Thrip. It has been used in long-running cyber-espionage operations targeting government, defense, and other strategic organizations in Asia, including activity against a digital certificate authority. Hannotog has also been observed alongside the related Billbug backdoor Sagerunex and with loader components deployed on victim systems.
Hannotog is used after compromise to establish persistent remote access and prepare infected hosts for follow-on operations. Reported behavior includes creating a new Windows service for persistence, modifying local firewall settings with native system commands to open a listening UDP port, stopping services, executing shell commands through the Windows command interpreter, downloading additional files, gathering system information, and uploading encrypted data to operators. It has been described as frequently serving a loader-like role by preparing victim systems and deploying secondary payloads such as Sagerunex.
Operationally, Hannotog has been tied to intrusions in which the threat actor likely gained initial access by exploiting public-facing applications and then combined custom malware with living-off-the-land and dual-use tools for reconnaissance, lateral movement, and sustained access. Its use of non-standard listening ports, service-based persistence, firewall modification, and encrypted data transfer reflects an emphasis on stealthy post-compromise control in support of intelligence collection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
In activity documented by Symantec in 2019, we detailed how the group was using a backdoor known as Hannotog (Backdoor.Hannotog) and another backdoor known as Sagerunex (Backdoor.Sagerunex). Both these tools were also seen in this more recent activity.
17 distinct techniques documented for this family, organized by ATT&CK tactic.
“Tools such as WMI, PsExec, and PowerShell are used to move laterally.”
The tools that were reportedly used by Billbug APT are the following: ... PowerShell
23 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Loader used to prepare hosts (service creation, firewall modification) and deploy secondary payloads, notably Sagerunex.
Custom backdoor malware used by the Billbug (aka Lotus Blossom/Thrip) APT for espionage-oriented access on compromised systems.
A backdoor used by Billbug that is deployed via loader files and appears to also function as a loader for Sagerunex. It can modify firewall settings, listen on port 5900, create services for persistence, stop services, upload encrypted data, execute shell commands for system reconnaissance, and download files.
Backdoor used by Billbug; multiple files believed to be loaders for Hannotog were found on victim machines, and it appears capable of dropping or starting Sagerunex on compromised systems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.