APT32__2020__OceanLotus_Extending_Cyber_Espionage_Operations_Through_Fake_Websites_Volexity.pdf
ID: 0b5b297c-5a57-4883-8465-e3c34794e6f9
STIX ID: report--0b5b297c-5a57-4883-8465-e3c34794e6f9
Threat Score
88/100
Uploaded: 2026-08-14
Published Date: 2020-11-11
Last Modified Date: 2020-11-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Volexity details an active OceanLotus espionage campaign where the actor operates numerous convincing fake news websites and Facebook pages to profile visitors and socially engineer Windows, macOS, and mobile victims into downloading implants or submitting credentials; the report includes analysis of malicious JavaScript, a RAR-delivered Cobalt Strike chain (Flash_Adobe_Install.rar → Flash_Adobe_Install.exe + hidden goopdate.dll loader), decoded C2 strings, and a long list of domains, hostnames, and file hashes as IOCs.
