Threat actor · all actors
Lotus BlossomG0030 state
🇨🇳 CN
aka Lotus Blossom, DRAGONFISH, Spring Dragon, RADIUM, Raspberry Typhoon, Bilbug, Thrip, LOTUS PANDA, ST Group, BRONZE ELGIN, ATK1, G0030, Red Salamander, Billbug
Last updated: 2026-08-20
About this actor
Microsoft has tracked Raspberry Typhoon (RADIUM) as the primary threat group targeting nations that ring the South China Sea. Raspberry Typhoon consistently targets government ministries, military entities, and corporate entities connected to critical infrastructure, particularly telecoms. Since January 2023, Raspberry Typhoon has been particularly persistent. When targeting government ministries or infrastructure, Raspberry Typhoon typically conducts intelligence collection and malware execution. In many countries, targets vary from defense and intelligence-related ministries to economic and trade-related ministries
Source: MITRE ATT&CK
Names & naming systems
Each vendor coins its own name for the same actor. Where a name follows a known scheme we attribute it; the rest are listed honestly as unclassified.
MITRE ATT&CKG-number catalogue id
Microsoftweather-system names
CrowdStrikenation-animal names
Secureworkscolour-metal names
Unclassifiedno scheme matched
How we know this
- Data origin
- MITRE ATT&CK Imported from the MITRE ATT&CK STIX bundle as an intrusion-set object.
- Techniques
- MITRE ATT&CK STIX mappings — 27 ATT&CK techniques on file.
- Named victims
- None on file.
See how actor data is built for the full pipeline.
Activity timeline
- 2022 — 1 KEV added
- 2010 — 1 CVE published
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
CVE-2010-2883 KEV | 8.1 | 7.3 | 0.9607 | 2010-09-09 | see CVE |
T1012Query Registry ↗T1016System Network Configuration Discovery ↗T1016.001Internet Connection Discovery ↗T1018Remote System Discovery ↗T1046Network Service Discovery ↗T1047Windows Management Instrumentation ↗T1049System Network Connections Discovery ↗T1074Data Staged ↗T1074.001Local Data Staging ↗T1083File and Directory Discovery ↗T1087Account Discovery ↗T1087.001Local Account ↗T1087.002Domain Account ↗T1090Proxy ↗T1090.001Internal Proxy ↗T1090.003Multi-hop Proxy ↗T1112Modify Registry ↗T1134Access Token Manipulation ↗T1482Domain Trust Discovery ↗T1539Steal Web Session Cookie ↗T1543Create or Modify System Process ↗T1543.003Windows Service ↗T1560Archive Collected Data ↗T1560.001Archive via Utility ↗T1560.003Archive via Custom Method ↗T1588Obtain Capabilities ↗T1588.002Tool ↗
Mitigating controls (NIST 800-53)
| Control | Techniques covered | Coverage |
|---|---|---|
CM-6 | 12 / 27 | 44% |
CM-7 | 11 / 27 | 41% |
SI-4 | 11 / 27 | 41% |
CM-2 | 10 / 27 | 37% |
SI-3 | 8 / 27 | 30% |
AC-3 | 7 / 27 | 26% |
SC-7 | 7 / 27 | 26% |
AC-6 | 6 / 27 | 22% |
CA-7 | 6 / 27 | 22% |
RA-5 | 6 / 27 | 22% |
AC-2 | 5 / 27 | 19% |
AC-4 | 5 / 27 | 19% |
IA-2 | 5 / 27 | 19% |
AC-5 | 4 / 27 | 15% |
CM-5 | 4 / 27 | 15% |
Co-occurring actors
- Scarlet Mimic 1 shared CVEs
Similar actors
Similar TTPs
- FunnyDream 0.21
- Operation CuckooBees 0.21
- Volt Typhoon 0.20
- FIN13 0.20
- Operation Wocao 0.20
Overlapping CVEs
- Scarlet Mimic 0.33
Active in same years
- APT29 2.00
- Naikon 2.00
- Equation 2.00
- Threat Group-3390 2.00
- Scarlet Mimic 2.00
Same nation-state
- Night Dragon 1.00
- FunnyDream 1.00
- Operation Wocao 1.00
- C0017 1.00
- Cutting Edge 1.00
Same category
- Night Dragon 1.00
- FunnyDream 1.00
- C0011 1.00
- Operation Wocao 1.00
- Operation Dream Job 1.00