China-linked Lotus Blossom APT targets governments and industries in Asian countries with new Sagerunex backdoor variants.Lotus Blossom APT has been using the Sagerunex backdoor since at least 2016.Two new Sagerunex backdoor variants use cloud services like Dropbox, Twitter, and Zimbra for C2 communication.Lotus Blossom group employs various tools and tactics to evade detection and achieve their objectives.