Skip to main content

Boteraser | Website and Server Security Solutions

Unidentified JS 001 (APT32 Profiler)

Malware

⚠️ Overview

Unidentified JS 001 (APT32 Profiler) is a JavaScript-based reconnaissance and profiling tool associated with the APT32 threat group, also tracked as OceanLotus or SeaLotus, a state-sponsored entity attributed to Vietnam. First documented by FireEye in 2015, this tool falls under the category of a backdoor and information stealer, specifically designed to collect system intelligence and support follow-on exploitation. It operates as a lightweight initial access payload delivered via spear-phishing emails or watering-hole attacks.

🔧 Technical Capabilities

The profiler uses JavaScript executed within Windows Script Host or embedded in Microsoft Office documents via macro to enumerate host data including operating system version, installed antivirus products, user domain, and processes. It communicates with a command-and-control (C2) server over HTTP or HTTPS, often masquerading as legitimate web traffic by using benign-looking User-Agent strings such as "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36". Persistence is achieved through scheduled tasks or registry run keys under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. Evasion techniques include obfuscation via variable renaming, string splitting, and encoding with base64 or custom XOR algorithms to bypass signature-based detection. MITRE ATT&CK techniques employed include T1059.007 (Command and Scripting Interpreter: JavaScript), T1087.001 (Account Discovery: Local Account), and T1057 (Process Discovery).

📜 History & Notable Incidents

APT32 has used this profiler in multiple campaigns targeting foreign governments, human rights organizations, and maritime industry entities across Southeast Asia, the United States, and Europe. A notable incident in 2018 involved the targeting of a Philippine government agency, where the profiler was delivered via a malicious Word document exploiting CVE-2017-0199 (Microsoft Office OLE2Link vulnerability). No law enforcement actions have been publicly linked to this specific tool, but the group remains under active monitoring by entities like the Cybersecurity and Infrastructure Security Agency (CISA) and Cisco Talos.

🔍 Detection Indicators

Behavioral signatures include the creation of scheduled tasks named "SystemCheck" or "UpdateService" and network connections to domains such as "update.microsoft-verify[.]com" or "support-ssl-check[.]net". Known file hashes are not consistently published due to the tool's polymorphic nature, but YARA rules from the FireEye threat intelligence team detect features like embedded JavaScript with calls to GetObject("winmgmts:") and new ActiveXObject("Microsoft.XMLHTTP").

☠️ Risk & Impact

The profiler facilitates large-scale data exfiltration by providing attackers with detailed victim-machine inventories, enabling tailored payloads for privilege escalation or lateral movement. Financial losses have not been quantified, but the tool's use in espionage campaigns has compromised sensitive diplomatic and intellectual property data. Affected sectors include government, energy, maritime, and human rights NGOs.

🛡️ Mitigation

Defenders should block execution of JavaScript from Office documents via Group Policy, deploy endpoint detection and response (EDR) rules for suspicious wscript.exe or cscript.exe child processes, and monitor for HTTP POST requests to unknown domains with JSON-formatted system data. CISA’s advisory AA19-092A recommends implementing application allowlisting and phishing-resistant multi-factor authentication.

Malware Threat Protection

Is Your Site Protected Against Malware-Driven Bot Traffic?

Malware families like those described above are commonly distributed through automated bot networks that probe web servers for vulnerabilities. Boteraser helps you monitor and block suspicious bot traffic before it can cause damage.

Run Free Bot Scan →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.