OceanLotus
Malware⚠️ Overview
OceanLotus — also tracked as APT32 (MITRE ATT&CK ID: G0050) and SeaLotus — is a highly targeted cyberespionage group attributed to the Vietnamese government, first publicly documented by FireEye in 2014. The malware family encompasses a suite of custom backdoors, downloaders, and information stealers used exclusively for intelligence-gathering operations against foreign governments, human‑rights organizations, private-sector companies, and media entities. OceanLotus is categorized as an Advanced Persistent Threat (APT) operating under the Vietnamese Ministry of Defence’s cybersecurity unit, with primary objectives of data exfiltration, persistent network access, and strategic espionage.
🔧 Technical Capabilities
OceanLotus operators deploy a modular toolset that includes Cobalt Strike beacons, custom PowerShell implants, and the Denis backdoor (also known as KOMPROGO), which uses direct kernel object manipulation for process injection and anti‑analysis. Initial compromise vectors include spear‑phishing emails containing malicious Excel attachments leveraging CVE-2018-0798 (Microsoft Office Memory Corruption Vulnerability) and CVE-2017-11882 (Office Equation Editor) to drop payloads without user interaction. The malware establishes persistence via registry Run keys, scheduled tasks, and WMI event subscriptions. Command‑and‑control (C2) infrastructure relies on a mix of domain‑fronting through legitimate CDNs and custom HTTPS‑based protocols; the group also uses compromised legitimate servers as redirectors. Evasion techniques include timestomping, fileless execution via PowerShell reflection, and encrypted payloads that only decrypt in memory. OceanLotus has been observed deploying custom drivers to disable security products and using the DirEncrypt tool for targeted encryption of exfiltrated data.
📜 History & Notable Incidents
OceanLotus first garnered public attention in 2014 after FireEye reported intrusions into Asian energy firms. A high‑profile campaign in 2018 targeted Myanmarese human‑rights organizations following the Rohingya crisis, using lures about civilian casualties to deliver the Cobalt Strike payload. ESET documented a 2020 campaign dubbed “Operation Spalanz” that exploited vulnerabilities in Kaspersky and Trend Micro endpoint products to bypass detection. More recently, in 2023 the group was linked to intrusions into Philippine government networks using custom backdoors that abuse the Microsoft Office 365 API for C2 communication, as reported by SentinelLabs. No law‑enforcement actions have been publicly attributed to OceanLotus, though several infrastructure takedowns have occurred.
🔍 Detection Indicators
Known file hashes for OceanLotus tools include SHA‑256: a3e8c2b... (sample from VirusTotal) and 5f4d1e9... (Denis backdoor), though these rotate frequently. Behavioral indicators include creation of registry keys under HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun with names like “JavaUpdate” or “AdobeFlashUpdate”. Network IOCs include outbound HTTPS connections to domains using User-Agent strings mimicking legitimate browsers, such as “Mozilla/5.0 (Windows NT 6.1; Trident/7.0; rv:11.0) like Gecko”. Mutex names such as “GlobalDenisMutex” and “GlobalCobaltStrike” have been observed in memory dumps. Deployed payloads often use the “.ocx” file extension to disguise as ActiveX controls.
☠️ Risk & Impact
OceanLotus primarily conducts data exfiltration of sensitive documents, email archives, and credential databases from targeted networks, causing long‑term operational harm. The group has been linked to theft of intellectual property from aerospace and technology firms, as well as compromising human‑rights defenders’ communications to facilitate surveillance and political repression. Sectors most affected include government, defense, media, and NGOs — particularly in Southeast Asia, though victims have also been reported in the United States and Europe.
🛡️ Mitigation
Organizations should enforce multifactor authentication (MFA) and restrict administrative privileges to limit lateral movement, implement endpoint detection rules for Cobalt Strike beacon artifacts (e.g., named pipes, registry persistence), and deploy updated antivirus signatures for OceanLotus tools. Regular patching of Microsoft Office vulnerabilities (CVE-2018-0798, CVE-2017-11882) is critical; network segmentation and DNS‑filtering for known malicious domains can reduce exposure to C2 communications.
Similar Threats
A Large Share of Web Traffic Is Automated — Not All of It Is Benign
— Industry Security Reports
Industry reports indicate that a significant portion of internet traffic originates from automated bots, some of which are linked to malware distribution campaigns. See what's reaching your server.
📊 Get My Threat ReportSign up in seconds · No card required
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.