logo

NanHaiShu: RATing the South China Sea

ID: 581dde2b-0030-4b8e-87e5-da9eb31da670

STIX ID: report--581dde2b-0030-4b8e-87e5-da9eb31da670

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2016-08-05

Last Modified Date: 2016-08-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
F-Secure Labs' whitepaper analyzes NanHaiShu, a Remote Access Trojan delivered via spearphishing Office documents containing VBA macros that decode and run embedded JScript/HTA payloads. The report documents targeted espionage against entities involved in the South China Sea arbitration (e.g., the Philippines DOJ, APEC organizers, an international law firm), describes technical and behavioral indicators (persistence, data collection, HTTP-based C2, obfuscation), provides sample hashes and C2 records, and assesses likely Chinese origin based on code artifacts, infrastructure changes, and target selection.