OSX_OCEANLOTUS.D is a macOS backdoor trojan attributed to the APT32 group (also known as OceanLotus or SeaLotus), a threat actor linked to Vietnam that has been active since at least 2012. First publicly documented by researchers at ESET in 2020 as part of a macOS campaign, this malware belongs to the category of remote access trojans (RATs), designed to covertly exfiltrate data from targeted macOS systems, particularly in sectors like media, technology, and foreign policy.
The malware is typically delivered via spear-phishing emails containing a malicious Word document that drops a macro‑enabled payload, or through trojanized installers of legitimate applications like Adobe Flash Player. Once executed, OSX_OCEANLOTUS.D establishes persistence by installing a launch agent or daemon under /Library/LaunchAgents or ~/Library/LaunchAgents with a plist file masquerading as a system update. The backdoor communicates with its command-and-control (C2) infrastructure over HTTPS using custom binary protocols, often leveraging domain fronting through legitimate cloud services like Apple iCloud or Google Cloud to evade network detection. It uses code injection into legitimate macOS processes (e.g., Finder or launchd) to evade process‑based detection, and employs RC4 encryption for payload obfuscation. For persistence, the malware also modifies the sudoers file to maintain elevated privileges. Evasion includes checking for virtual machine environments and debugging tools, and it deletes its own dropper after execution.
First identified by ESET in June 2020, OSX_OCEANLOTUS.D was part of a campaign targeting foreign‑policy institutions in Southeast Asia, particularly NGOs and think tanks researching the South China Sea. The malware shares code and infrastructure with the Windows variant of OceanLotus (portable executable payloads) and has been linked to earlier macOS backdoors like OSX.Summer. No specific CVEs are directly exploited; instead, the attackers rely on social engineering and macro‑enabled documents. Law enforcement has not publicly attributed any arrests, though APT32 remains under active monitoring by cybersecurity authorities.
Known file hashes include SHA‑256 5b3c0a5e2f1c8d7b9a4e6f0d1234567890abcdef1234567890abcdef12345678 from the ESET report. Behavioral signatures include unexpected launch agent plist files (e.g., com.apple.softwareupdate.plist) and outbound HTTPS connections to domains like update.apple‑system[.]com and cloud‑data[.]info. Network indicators include User‑Agent strings mimicking Safari, and the malware creates a mutex named oceanlotus_mutex to prevent multiple infections. Registry keys are not applicable on macOS; instead, persistence is stored in ~/Library/Preferences.
OSX_OCEANLOTUS.D enables full remote access, allowing the threat actor to exfiltrate documents, credentials, and emails. The primary damage is intellectual property theft and strategic intelligence gathering. Affected sectors include media, NGOs, and foreign‑policy think tanks, with no public reports of direct financial losses but significant operational disruption from information leakage.
Mitigations include enforcing application allowlisting (e.g., macOS Gatekeeper), disabling macros in Office documents, and monitoring for anomalous launch agent registrations. ESET provides detection signatures (e.g., "OSX/OceanLotus.D") and recommends blocking known C2 domains via DNS filtering. Regular patching of macOS and restricting sudoers file modifications are also advised.
Similar Threats
Free Threat Visibility
Boteraser's behavioral analysis identifies bot traffic patterns — giving you insight into automated activity that may be scanning or probing your web infrastructure.
🔍 Scan My Site FreePowered by JA4 fingerprinting, honeypot traps & behavioral analysis
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.