logo

The SpyRATs of OceanLotus Malware Analysis White Paper

ID: 93d79cdd-bdac-4397-98c8-c79a870e7c8d

STIX ID: report--93d79cdd-bdac-4397-98c8-c79a870e7c8d

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2018-10-17

Last Modified Date: 2018-10-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This Cylance white paper analyzes OceanLotus (APT32) activity and tooling, documenting multiple custom RATs (Roland, Remy, Splinter), Cobalt Strike Beacon variants, and additional backdoors (Rizzo, Denis) used in 2017–2018 intrusions; it provides deep technical details on payload delivery (PowerShell one‑liners, MSFvenom/Veil/DKMC), in‑memory loaders, C2 protocols (TCP/HTTP/S with proxy/auth, named pipes, ICMP, DNS tunneling), command sets, compression/encoding schemes, and extensive IOCs (domains, IPs, hashes) to support detection and response.