logo

APT32__2019__OceanLotus_Attacks_to_Indochinese_Peninsula.pdf

ID: 18d641c0-e03c-4f1f-8491-326092d5f5cd

STIX ID: report--18d641c0-e03c-4f1f-8491-326092d5f5cd

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2019-05-09

Last Modified Date: 2019-05-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This QiAnXin / RedDrip threat intelligence report documents OceanLotus (APT-C-00) operations against Indochinese targets since 2018, detailing phishing with weaponized Office macros and template injection, exploitation of EternalBlue and WinRAR flaws, custom Windows droppers (DLL hijacks, in-memory loaders, Cobalt Strike modules) and macOS backdoors disguised as browser installers; the report includes technical analysis, sample behaviors, attack workflows and a long list of domains, file hashes and other IOCs to support detection and response.