This technical report presents findings from Cisco Talos regarding multiple cyber espionage campaigns named Lotus Blossom, which have targeted various sectors including government, manufacturing, telecommunications, and media organizations. The report details the use of Sagerunex hacking tools and the development of new variants that utilize both traditional command-and-control (C&C) servers and legitimate third-party cloud services for malicious activities. The analysis identifies numerous indicators of compromise (IoCs), including 10 domains and 28 IP addresses, which were further expanded through a DNS deep dive. The report outlines the creation dates, registrars, and geographical locations of these IoCs, revealing that many were registered recently. Additionally, the report documents the historical domain-to-IP resolutions and the geolocation of the identified IP addresses, providing insights into their potential malicious use. The findings indicate that several artifacts have already been weaponized for attacks, emphasizing the ongoing threat posed by the Lotus Blossom group.