September 22, 2023

Billbug, a chinese state sponsored-hacking group has breached government and defence agencies throughout Asia, as part of a major campaign since March. The gang infiltrated a digital certificate authority, which could lead to Billbug accessing huge amounts of secure internet traffic.

Also been referred to as Thrip, Lotus Blossom, Lotus Panda and Spring Dragon, and has previously been accused of infiltrating organisations in Hong Kong, Macau, Indonesia, Malaysia, the Philippines and Vietnam.

Researchers estimate that this particular campaign is predominantly for information gathering. The targeting of government agencies is most likely driven by espionage motivations,The threat group remains a skilled and well-resourced operator that is capable of carrying out sustained and wide-ranging campaigns.


The threat actor also managed to infiltrate a digital certificate authority. The certificate authority was likely targeted in order to steal legitimate digital certificates.

This would allow Billbug to potentially use compromised certificates to intercept HTTPS traffic, referring to the protocol used by secure websites.

Researchers not found any evidence of this yet, however, and says it has notified the certificate authority in question.

This research was documented by researchers from symantec

