logo

Stairwell threat report - The origin of APT32 macros

ID: 991f0cdf-da5c-4b78-becb-fc6104446369

STIX ID: report--991f0cdf-da5c-4b78-becb-fc6104446369

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2022-04-29

Last Modified Date: 2022-04-29

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Stairwell's report dissects a 2017 leaked RAR named “StrikeSuite Gift” containing source code, macros, shellcode, and tooling used to build Office-lure malware; it documents developer artifacts, debug symbols, PDB paths, scheduled-task XML timestamps, obfuscation routines, and network indicators, and ties components (notably a ShellcodeLoader L.dll and XML timestamps) to APT32/OceanLotus, providing YARA rules and guidance to detect related artifacts.