Pulse Report: New APT32 Malware Campaign Targets Cambodian Government
ID: 601b50a3-834a-4922-bb0b-cdd602780e67
STIX ID: report--601b50a3-834a-4922-bb0b-cdd602780e67
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2020-11-09
Last Modified Date: 2020-11-09
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future's Insikt Group reports a new APT32 (OceanLotus) campaign targeting Cambodian government organizations using ASEAN-themed spearphishing; the malware is delivered via self-extracting archives that sideload a malicious DLL which extracts and executes encrypted shellcode, and researchers provide active C2 IPs/domains, multiple malware hashes, and a YARA rule to aid detection.
