ESET_OceanLotus.pdf
ID: 2e8392bb-8b26-4e10-82ac-98de086193bf
STIX ID: report--2e8392bb-8b26-4e10-82ac-98de086193bf
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2018-03-13
Last Modified Date: 2018-03-13
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**OceanLotus (APT32) backdoor analysis:** ESET documents a targeted multi‑stage campaign against East‑Asian organizations that uses deceptive droppers and fake installers, LZMA/RC4/encrypted shellcode-based PE loaders, DLL side‑loading of signed Symantec/McAfee binaries to execute a persistent backdoor, custom C2 mechanisms (TCP on port 25123 and an HTTPprov fallback using libcurl), extensive control‑flow obfuscation and a broad set of post‑compromise capabilities; the report includes detailed IoCs (hashes, domains, IPs, registry keys) and remediation indicators.
