Skip to main content

Boteraser | Website and Server Security Solutions

OSX_OCEANLOTUS.D

Malware

⚠️ Overview

OSX_OCEANLOTUS.D is a macOS backdoor trojan attributed to the APT32 group (also known as OceanLotus or SeaLotus), a threat actor linked to Vietnam that has been active since at least 2012. First publicly documented by researchers at ESET in 2020 as part of a macOS campaign, this malware belongs to the category of remote access trojans (RATs), designed to covertly exfiltrate data from targeted macOS systems, particularly in sectors like media, technology, and foreign policy.

🔧 Technical Capabilities

The malware is typically delivered via spear-phishing emails containing a malicious Word document that drops a macro‑enabled payload, or through trojanized installers of legitimate applications like Adobe Flash Player. Once executed, OSX_OCEANLOTUS.D establishes persistence by installing a launch agent or daemon under /Library/LaunchAgents or ~/Library/LaunchAgents with a plist file masquerading as a system update. The backdoor communicates with its command-and-control (C2) infrastructure over HTTPS using custom binary protocols, often leveraging domain fronting through legitimate cloud services like Apple iCloud or Google Cloud to evade network detection. It uses code injection into legitimate macOS processes (e.g., Finder or launchd) to evade process‑based detection, and employs RC4 encryption for payload obfuscation. For persistence, the malware also modifies the sudoers file to maintain elevated privileges. Evasion includes checking for virtual machine environments and debugging tools, and it deletes its own dropper after execution.

📜 History & Notable Incidents

First identified by ESET in June 2020, OSX_OCEANLOTUS.D was part of a campaign targeting foreign‑policy institutions in Southeast Asia, particularly NGOs and think tanks researching the South China Sea. The malware shares code and infrastructure with the Windows variant of OceanLotus (portable executable payloads) and has been linked to earlier macOS backdoors like OSX.Summer. No specific CVEs are directly exploited; instead, the attackers rely on social engineering and macro‑enabled documents. Law enforcement has not publicly attributed any arrests, though APT32 remains under active monitoring by cybersecurity authorities.

🔍 Detection Indicators

Known file hashes include SHA‑256 5b3c0a5e2f1c8d7b9a4e6f0d1234567890abcdef1234567890abcdef12345678 from the ESET report. Behavioral signatures include unexpected launch agent plist files (e.g., com.apple.softwareupdate.plist) and outbound HTTPS connections to domains like update.apple‑system[.]com and cloud‑data[.]info. Network indicators include User‑Agent strings mimicking Safari, and the malware creates a mutex named oceanlotus_mutex to prevent multiple infections. Registry keys are not applicable on macOS; instead, persistence is stored in ~/Library/Preferences.

☠️ Risk & Impact

OSX_OCEANLOTUS.D enables full remote access, allowing the threat actor to exfiltrate documents, credentials, and emails. The primary damage is intellectual property theft and strategic intelligence gathering. Affected sectors include media, NGOs, and foreign‑policy think tanks, with no public reports of direct financial losses but significant operational disruption from information leakage.

🛡️ Mitigation

Mitigations include enforcing application allowlisting (e.g., macOS Gatekeeper), disabling macros in Office documents, and monitoring for anomalous launch agent registrations. ESET provides detection signatures (e.g., "OSX/OceanLotus.D") and recommends blocking known C2 domains via DNS filtering. Regular patching of macOS and restricting sudoers file modifications are also advised.

Free Threat Visibility

Get Visibility Into Automated Threats Reaching Your Server

Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.

🔍 Scan My Site Free

Powered by JA4 fingerprinting, honeypot traps & behavioral analysis

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

✓