Unidentified JS 001 (APT32 Profiler) is a JavaScript-based reconnaissance and profiling tool associated with the APT32 threat group, also tracked as OceanLotus or SeaLotus, a state-sponsored entity attributed to Vietnam. First documented by FireEye in 2015, this tool falls under the category of a backdoor and information stealer, specifically designed to collect system intelligence and support follow-on exploitation. It operates as a lightweight initial access payload delivered via spear-phishing emails or watering-hole attacks.
The profiler uses JavaScript executed within Windows Script Host or embedded in Microsoft Office documents via macro to enumerate host data including operating system version, installed antivirus products, user domain, and processes. It communicates with a command-and-control (C2) server over HTTP or HTTPS, often masquerading as legitimate web traffic by using benign-looking User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Persistence is achieved through scheduled tasks or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation via variable renaming, string splitting, and encoding with base64 or custom XOR algorithms to bypass signature-based detection. MITRE ATT&CK techniques employed include T1059.007 (Command and Scripting Interpreter: JavaScript), T1087.001 (Account Discovery: Local Account), and T1057 (Process Discovery).
APT32 has used this profiler in multiple campaigns targeting foreign governments, human rights organizations, and maritime industry entities across Southeast Asia, the United States, and Europe. A notable incident in 2018 involved the targeting of a Philippine government agency, where the profiler was delivered via a malicious Word document exploiting CVE-2017-0199 (Microsoft Office OLE2Link vulnerability). No law enforcement actions have been publicly linked to this specific tool, but the group remains under active monitoring by entities like the Cybersecurity and Infrastructure Security Agency (CISA) and Cisco Talos.
Behavioral signatures include the creation of scheduled tasks named "SystemCheck" or "UpdateService" and network connections to domains such as "update.microsoft-verify[.]com" or "support-ssl-check[.]net". Known file hashes are not consistently published due to the tool's polymorphic nature, but YARA rules from the FireEye threat intelligence team detect features like embedded JavaScript with calls to GetObject("winmgmts:") and new ActiveXObject("Microsoft.XMLHTTP").
The profiler facilitates large-scale data exfiltration by providing attackers with detailed victim-machine inventories, enabling tailored payloads for privilege escalation or lateral movement. Financial losses have not been quantified, but the tool's use in espionage campaigns has compromised sensitive diplomatic and intellectual property data. Affected sectors include government, energy, maritime, and human rights NGOs.
Defenders should block execution of JavaScript from Office documents via Group Policy, deploy endpoint detection and response (EDR) rules for suspicious wscript.exe or cscript.exe child processes, and monitor for HTTP POST requests to unknown domains with JSON-formatted system data. CISA’s advisory AA19-092A recommends implementing application allowlisting and phishing-resistant multi-factor authentication.
Similar Threats
Malware Threat Protection
Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.