Threat Group Cards: A Threat Actor Encyclopedia Archived: 2026-04-05 19:26:41 UTC Home > List all groups > List all tools > List all groups using tool Hannotog Tool: Hannotog Names Hannotog Category Malware Type Backdoor Description (Symantec) Hannotog is a custom backdoor which provides the attackers with a persistent presence on the victim’s network. It has been used in conjunction with several other Thrip tools, including Sagerunex, another custom backdoor providing remote access to the attackers, and Catchamas (Infostealer.Catchamas), a custom Trojan deployed on selected computers of interest and designed to steal information. Information MITRE ATT&CK AlienVault OTX Last change to this tool card: 28 June 2025 Download this tool card in JSON format All groups using tool Hannotog Changed Name Country Observed APT groups   Lotus Blossom, Spring Dragon, Thrip 2012-Aug 2024   1 group listed (1 APT, 0 other, 0 unknown) Source: https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebfe7812-f35c-4b59-add3-7e06fb8f8aab https://apt.etda.or.th/cgi-bin/listgroups.cgi?u=ebfe7812-f35c-4b59-add3-7e06fb8f8aab Page 1 of 1