Lotus Blossom is a highly disciplined Chinese state-sponsored cyber espionage group active since at least 2009. Also known by numerous aliases such as Esitert, Billbug, Spring Dragon, and Thrip, the group primarily targets governmental, military, and economic entities, with a historical focus on Southeast Asia, though recent operations demonstrate a broader global reach. Their primary motivation is intelligence gathering, aiming to steal sensitive information. The group is characterized by its long-term persistence, strategic targeting, and a methodical approach to technical evolution, often leveraging legitimate tools and established trust relationships to maintain covert access within compromised networks. A notable aspect distinguishing them is their recent shift towards sophisticated supply chain attacks.