logo

APT32__2020__OceanLotus_Extending_Cyber_Espionage_Operations_Through_Fake_Websites_Volexity.pdf

ID: 0b5b297c-5a57-4883-8465-e3c34794e6f9

STIX ID: report--0b5b297c-5a57-4883-8465-e3c34794e6f9

Threat Score

88/100

Uploaded: 2026-08-14

Published Date: 2020-11-11

Last Modified Date: 2020-11-11

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity details an active OceanLotus espionage campaign where the actor operates numerous convincing fake news websites and Facebook pages to profile visitors and socially engineer Windows, macOS, and mobile victims into downloading implants or submitting credentials; the report includes analysis of malicious JavaScript, a RAR-delivered Cobalt Strike chain (Flash_Adobe_Install.rar → Flash_Adobe_Install.exe + hidden goopdate.dll loader), decoded C2 strings, and a long list of domains, hostnames, and file hashes as IOCs.