NanHaiShu: RATing the South China Sea
ID: 581dde2b-0030-4b8e-87e5-da9eb31da670
STIX ID: report--581dde2b-0030-4b8e-87e5-da9eb31da670
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2016-08-05
Last Modified Date: 2016-08-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F-Secure Labs' whitepaper analyzes NanHaiShu, a Remote Access Trojan delivered via spearphishing Office documents containing VBA macros that decode and run embedded JScript/HTA payloads. The report documents targeted espionage against entities involved in the South China Sea arbitration (e.g., the Philippines DOJ, APEC organizers, an international law firm), describes technical and behavioral indicators (persistence, data collection, HTTP-based C2, obfuscation), provides sample hashes and C2 records, and assesses likely Chinese origin based on code artifacts, infrastructure changes, and target selection.
