logo

Pulse Report: New APT32 Malware Campaign Targets Cambodian Government

ID: 601b50a3-834a-4922-bb0b-cdd602780e67

STIX ID: report--601b50a3-834a-4922-bb0b-cdd602780e67

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2020-11-09

Last Modified Date: 2020-11-09

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports a new APT32 (OceanLotus) campaign targeting Cambodian government organizations using ASEAN-themed spearphishing; the malware is delivered via self-extracting archives that sideload a malicious DLL which extracts and executes encrypted shellcode, and researchers provide active C2 IPs/domains, multiple malware hashes, and a YARA rule to aid detection.