LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0081: Elise

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.[1][2]

EnterpriseS0081MalwareObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

Elise matters because ATT&CK identifies it as a custom Windows backdoor associated with Lotus Blossom, with related behaviors covering discovery, persistence, defense evasion, command-and-control, tool transfer, and local data staging. For leaders, the decision value is not the malware name alone; it is whether Windows endpoint, registry, service, process, file, and web-traffic telemetry can show how a backdoor established persistence, blended in, communicated, and prepared data or tooling for follow-on activity.

Executive priority

Treat Elise as a validation case for Windows intrusion readiness against a custom backdoor rather than as a standalone signature problem. Priority questions: can the organization prove coverage for suspicious Windows service or Run key persistence, rundll32/DLL-based execution, discovery activity, abnormal web-based C2, encoded or encrypted traffic patterns, and evidence cleanup such as file deletion or timestomping? These controls support incident scoping, audit evidence, resilience planning, and prioritization of endpoint and network visibility investments.

Technical view

ATT&CK lists Elise as Windows malware and relates it to Lotus Blossom. The relationship set maps Elise to discovery techniques including system service, network configuration, process, system information, file/directory, and local account discovery; persistence through Windows services and Registry Run keys/startup folder; stealth through encoded/encrypted files, resource-name masquerading, DLL injection, rundll32 abuse, file deletion, and timestomping; C2 over web protocols with standard encoding and symmetric cryptography; ingress tool transfer; and local data staging. SOC and IR teams should validate correlated Windows host telemetry and network telemetry across these behaviors instead of relying on one malware indicator.

Likely telemetry

  • Windows process creation and command-line telemetry, especially discovery utilities and rundll32 execution
  • Windows service creation/modification events and related registry changes
  • Registry Run key and Startup Folder modification events
  • DLL load, remote thread, or process injection-relevant endpoint telemetry where available
  • File creation, deletion, rename, path, and timestamp metadata, including evidence of timestomping or files placed in trusted-looking locations

Detection direction

  • Because ATT&CK provides no official detection text for Elise, build detections from the related techniques and validate them in the local Windows environment.
  • Correlate persistence events with nearby discovery commands, file placement, rundll32 execution, DLL activity, and outbound web traffic; isolated events may be administrative or benign.
  • Tune for common false positives from legitimate software installation, system administration, inventory tools, backup agents, and endpoint management platforms that create services, query processes, or enumerate configuration.
  • Review allowlists around rundll32.exe and trusted Windows directories; the related techniques indicate that legitimate names and locations may be abused to reduce visibility.
  • Validate retention and integrity of file metadata and endpoint logs, since file deletion and timestomping can weaken post-incident reconstruction.

Mitigation priorities

  • Prioritize Windows endpoint visibility and logging for service changes, Run key changes, process execution, DLL loading, and file metadata changes.
  • Restrict unnecessary privilege to create or modify Windows services and persistence locations; review administrative access paths that can enable these changes.
  • Apply application control or execution policy where feasible to reduce unauthorized DLL, rundll32, and unexpected binary execution from user-writable or suspicious paths.
  • Harden egress controls and monitor outbound web-protocol traffic so unusual C2-like communications are reviewable, not lost in normal HTTP/S volume.
  • Maintain incident response playbooks for backdoor cases that include persistence review, discovery activity reconstruction, network containment, staged-data search, and timeline validation for deleted or timestomped files.
Additional notes and limits

The most useful defensive framing is behavior-based: Elise is described as a custom backdoor, and the supplied relationships show a broad Windows intrusion pattern spanning persistence, stealth, discovery, C2, transfer, and staging. The Lotus Blossom relationship is relevant for intelligence context, especially because the related group is described as long-standing and targeting entities in Asia, including government-related targets and digital certificate issuers, but attribution requires separate evidence.

The ATT&CK object does not provide official detection guidance, tactics are not specified on the malware object itself, and aliases/labels are not supplied. Technique relationships indicate behaviors associated with Elise but do not prove that every sample or incident will exhibit all behaviors. Local telemetry, asset role, baseline activity, and incident evidence are required to determine exposure or detection coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Elise

Elise is a custom backdoor Trojan that appears to be used exclusively by Lotus Blossom. It is part of a larger group of tools referred to as LStudio, ST Group, and APT0LSTU.[1][2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

19 rows
DomainIDNameRelationship / procedure
EnterpriseT1036.005Match Legitimate Resource Name or LocationSub-technique

If installing itself as a service fails, Elise instead writes itself as a file named svchost.exe saved in %APPDATA%\Microsoft\Network.[1]

EnterpriseT1105Ingress Tool Transfer

Elise can download additional files from the C2 server for execution.[2]

EnterpriseT1082System Information Discovery

Elise executes systeminfo after initial communication is made to the remote server.[1]

EnterpriseT1573.001Symmetric CryptographySub-technique

Elise encrypts exfiltrated data with RC4.[1]

EnterpriseT1007System Service Discovery

Elise executes net start after initial communication is made to the remote server.[1]

EnterpriseT1543.003Windows ServiceSub-technique

Elise configures itself as a service.[1]

EnterpriseT1016System Network Configuration Discovery

Elise executes ipconfig /all after initial communication is made to the remote server.[1][2]

EnterpriseT1218.011Rundll32Sub-technique

After copying itself to a DLL file, a variant of Elise calls the DLL file using rundll32.exe.[1]

EnterpriseT1057Process Discovery

Elise enumerates processes via the tasklist command.[2]

EnterpriseT1027.013Encrypted/Encoded FileSub-technique

Elise encrypts several of its files, including configuration files.[1]

EnterpriseT1070.006TimestompSub-technique

Elise performs timestomping of a CAB file it creates.[1]

EnterpriseT1083File and Directory Discovery

A variant of Elise executes dir C:\progra~1 when initially run.[1][2]

EnterpriseT1074.001Local Data StagingSub-technique

Elise creates a file in AppData\Local\Microsoft\Windows\Explorer and stores all harvested data in that file.[2]

EnterpriseT1070.004File DeletionSub-technique

Elise is capable of launching a remote shell on the host to delete itself.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

Elise communicates over HTTP or HTTPS for C2.[1]

EnterpriseT1132.001Standard EncodingSub-technique

Elise exfiltrates data using cookie values that are Base64-encoded.[1]

EnterpriseT1087.001Local AccountSub-technique

Elise executes net user after initial communication is made to the remote server.[1]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

If establishing persistence by installation as a new service fails, one variant of Elise establishes persistence for the created .exe file by setting the following Registry key: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svchost : %APPDATA%\Microsoft\Network\svchost.exe. Other variants have set the following Registry keys for persistence: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\imejp : [self] and HKCU\Software\Microsoft\Windows\CurrentVersion\Run\IAStorD.[1][2]

EnterpriseT1055.001Dynamic-link Library InjectionSub-technique

Elise injects DLL files into iexplore.exe.[1][2]

Associated objects

Groups, software, and campaigns

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
5b753848d64e7311...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.3Current bundle5b753848d64e…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  2. [2]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  3. [3]
    Spring Dragon Jun 2015

    Baumgartner, K.. (2015, June 17). The Spring Dragon APT. Retrieved February 15, 2016.

    Open source URL
  4. [4]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  5. [5]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  6. [6]
    BKDR_ESILE

    (Citation: Lotus Blossom Jun 2015)

  7. [7]
    BKDR_ESILE

    (Citation: Lotus Blossom Jun 2015)

  8. [8]
    BKDR_ESILE

    (Citation: Lotus Blossom Jun 2015)

  9. [9]
    Elise

    (Citation: Accenture Dragonfish Jan 2018)

  10. [10]
    Elise

    (Citation: Accenture Dragonfish Jan 2018)

  11. [11]
    Elise

    (Citation: Accenture Dragonfish Jan 2018)

  12. [12]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  13. [13]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  14. [14]
    Page

    (Citation: Lotus Blossom Jun 2015)

  15. [15]
    Page

    (Citation: Lotus Blossom Jun 2015)

  16. [16]
    Page

    (Citation: Lotus Blossom Jun 2015)

  17. [17]
    mitre-attackS0081
    Open source URL
  18. [18]
    mitre-attackS0081
    Open source URL
  19. [19]
    mitre-attackS0081
    Open source URL
  20. [20]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  21. [21]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  22. [22]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  23. [23]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  24. [24]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  25. [25]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  26. [26]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  27. [27]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  28. [28]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  29. [29]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  30. [30]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  31. [31]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  32. [32]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  33. [33]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  34. [34]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  35. [35]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  36. [36]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  37. [37]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  38. [38]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  39. [39]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  40. [40]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  41. [41]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  42. [42]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  43. [43]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  44. [44]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  45. [45]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  46. [46]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  47. [47]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  48. [48]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  49. [49]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  50. [50]
    Spring Dragon Jun 2015

    Baumgartner, K.. (2015, June 17). The Spring Dragon APT. Retrieved February 15, 2016.

    Open source URL
  51. [51]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  52. [52]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  53. [53]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  54. [54]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  55. [55]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  56. [56]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  57. [57]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  58. [58]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  59. [59]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  60. [60]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  61. [61]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  62. [62]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
  63. [63]
    Accenture Dragonfish Jan 2018

    Accenture Security. (2018, January 27). DRAGONFISH DELIVERS NEW FORM OF ELISE MALWARE TARGETING ASEAN DEFENCE MINISTERS’ MEETING AND ASSOCIATES. Retrieved November 17, 2024.

    Open source URL
  64. [64]
    Lotus Blossom Jun 2015

    Falcone, R., et al.. (2015, June 16). Operation Lotus Blossom. Retrieved February 15, 2016.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.