The group hit government, air control and telco companies in Southeast Asia
Victims were not named
Lotus Panda never used before seen infosteals and loaders
Lotus Panda, a Chinese state -sponsored threat actor, managed to compromise more organizations in a number of Southeast Asian countries, in a campaign that took place between mid -mid -2024 and early 2025.
CyberSecurity scientists from the Symantec Threat Hunter team said the organizations included government agencies, air traffic management organizations, telecom operators and a construction company in a country, a news agency in another and an air freight organization in another. The sacrificial countries or organizations were not named.