logo

ESET_OceanLotus.pdf

ID: 2e8392bb-8b26-4e10-82ac-98de086193bf

STIX ID: report--2e8392bb-8b26-4e10-82ac-98de086193bf

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2018-03-13

Last Modified Date: 2018-03-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**OceanLotus (APT32) backdoor analysis:** ESET documents a targeted multi‑stage campaign against East‑Asian organizations that uses deceptive droppers and fake installers, LZMA/RC4/encrypted shellcode-based PE loaders, DLL side‑loading of signed Symantec/McAfee binaries to execute a persistent backdoor, custom C2 mechanisms (TCP on port 25123 and an HTTPprov fallback using libcurl), extensive control‑flow obfuscation and a broad set of post‑compromise capabilities; the report includes detailed IoCs (hashes, domains, IPs, registry keys) and remediation indicators.