IOC Radar
TLP:WHITE17 IOCs

The Chrysalis Backdoor: A Deep Dive into Lotus Blossom’s toolkit

BO
Botvrij.eu OSINT Feed
Published February 3, 2026Original Report

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYunknownINFRASTRUCTUREapi.wiresguard.com/ap…124.222.137.114:9999/…https://api.wiresguar…CAPABILITYCobalt StrikeVICTIMunknown
Adversary
Infrastructure(6)
Capability(1)
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise17

TypeIndicatorConfidenceScoreFirst Seen
URLapi.wiresguard.com/api/FileUpload/submit
c2loadermalware
High
68
Jun 2, 26
URL124.222.137.114:9999/3yZR31VK
c2malwarenetwork
High
68
Jun 2, 26
URLhttps://api.wiresguard.com/api/Info/submit
c2malwarenetwork
High
68
Jun 2, 26
URLhttps://api.wiresguard.com/api/getInfo/v1
c2malwarenetwork
High
68
Jun 2, 26
Domainapi.skycloudcenter.com
malwarenetwork
High
68
Jun 2, 26
IP124.222.137.114
loadermalwarenetwork
High
68
Jun 2, 26
IP61.4.102.97
loadermalwarenetwork
High
68
Jun 2, 26
IP59.110.7.32
botnetloadermalware
High
86
Jun 2, 26
URLhttp://59.110.7.32:8880/uffhxpSy
c2loadermalware
High
68
Jun 2, 26
URLhttps://api.wiresguard.com/users/system
c2malwarenetwork
High
68
Jun 2, 26
URLapi.wiresguard.com/update/v1
c2loadermalware
High
68
Jun 2, 26
URLhttp://124.222.137.114:9999/api/updateStatus/v1
c2malwarenetwork
High
68
Jun 2, 26
IP95.179.213.0
intel-blogmalwarenetwork
High
69
Jun 2, 26
URLhttp://59.110.7.32:8880/api/Metadata/submit
c2loadermalware
High
68
Jun 2, 26
URLhttps://notepad-plus-plus.org/news/hijacked-incident-info-update/
c2malwarenetwork
High
68
Jun 2, 26
URLhttp://59.110.7.32:8880/api/getBasicInfo/v1
c2loadermalware
High
68
Jun 2, 26
URLhttp://124.222.137.114:9999/api/Info/submit
c2malwarenetwork
High
68
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph17 total IOCs
URLDomainIP
URL12IP4Domain1Malware1REPORTThe Chrysalis Backdoor: A Cobalt Strike
scroll to zoom · drag to pan · click IOC to open