Deploy autonomous AI agents that reason, exploit, and validate complex vulnerability chains — not another scanner, an agentic system that thinks like a senior pentester.
Also known as: Lotus Blossom, Spring Dragon, Dragonfish, Billbug, Thrip, Bronze Elgin, CTG-8171, ATK 1, ATK 78, Red Salamander, G0030, G0076, ATK78
Spring Dragon is a long running APT actor that operates on a massive scale. The group has been running campaigns, mostly in countries and territories around the South China Sea, since as early as 2012. The main targets of Spring Dragon attacks are high profile governmental organizations and political parties, education institutions such as universities, as well as companies from the telecommunications sector. Spring Dragon is known for spear phishing and watering hole techniques and some of its tools have previously been analyzed and reported on by security researchers, including Kaspersky Lab. Operation Poisoned News, TwoSail Junk may be one of their campaigns.
No exploited CVEs have been attributed to this threat actor yet.
Browse CVE Database