The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog
ID: 1119d716-1630-425d-b68c-e6f3b0b03350
STIX ID: report--1119d716-1630-425d-b68c-e6f3b0b03350
Threat Score
82/100
Uploaded: 2026-08-21
Published Date: 2017-06-23
Last Modified Date: 2017-06-23
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
A detailed analysis of a sophisticated OceanLotus macOS backdoor that uses disguised application bundles and decoy documents for persistence, communicates with a custom encrypted C2 protocol on port 443 using a modular architecture that can load additional libraries, and targets victims in Vietnam with evidence of ongoing activity.
