The SpyRATs of OceanLotus Malware Analysis White Paper
ID: 93d79cdd-bdac-4397-98c8-c79a870e7c8d
STIX ID: report--93d79cdd-bdac-4397-98c8-c79a870e7c8d
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-10-17
Last Modified Date: 2018-10-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cylance white paper analyzes OceanLotus (APT32) activity and tooling, documenting multiple custom RATs (Roland, Remy, Splinter), Cobalt Strike Beacon variants, and additional backdoors (Rizzo, Denis) used in 2017–2018 intrusions; it provides deep technical details on payload delivery (PowerShell one‑liners, MSFvenom/Veil/DKMC), in‑memory loaders, C2 protocols (TCP/HTTP/S with proxy/auth, named pipes, ICMP, DNS tunneling), command sets, compression/encoding schemes, and extensive IOCs (domains, IPs, hashes) to support detection and response.
