OceanLotus Steganography Malware Analysis White Paper
ID: 998f2c2d-f6fc-4a79-bc5b-d2e43e1c7c73
STIX ID: report--998f2c2d-f6fc-4a79-bc5b-d2e43e1c7c73
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2019-03-28
Last Modified Date: 2019-03-28
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This white paper analyzes OceanLotus (APT32) use of custom steganographic PNG loaders that conceal AES128-encrypted payloads in image pixels, decrypt and XOR-deobfuscate them, then execute multi-stage backdoors (Denes and Remy variants). It documents two loader variants with anti-analysis and injection techniques, dissects the launcher, backdoor and C2 modules, and provides extensive IOCs (file hashes, embedded keys/IVs, C2 domains, registry paths), YARA rules and a Python decoder to aid detection and hunting.
