APT32__2019__OceanLotus_Attacks_to_Indochinese_Peninsula.pdf
ID: 18d641c0-e03c-4f1f-8491-326092d5f5cd
STIX ID: report--18d641c0-e03c-4f1f-8491-326092d5f5cd
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-05-09
Last Modified Date: 2019-05-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This QiAnXin / RedDrip threat intelligence report documents OceanLotus (APT-C-00) operations against Indochinese targets since 2018, detailing phishing with weaponized Office macros and template injection, exploitation of EternalBlue and WinRAR flaws, custom Windows droppers (DLL hijacks, in-memory loaders, Cobalt Strike modules) and macOS backdoors disguised as browser installers; the report includes technical analysis, sample behaviors, attack workflows and a long list of domains, file hashes and other IOCs to support detection and response.
