logo

OceanLotus Steganography Malware Analysis White Paper

ID: 998f2c2d-f6fc-4a79-bc5b-d2e43e1c7c73

STIX ID: report--998f2c2d-f6fc-4a79-bc5b-d2e43e1c7c73

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2019-03-28

Last Modified Date: 2019-03-28

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This white paper analyzes OceanLotus (APT32) use of custom steganographic PNG loaders that conceal AES128-encrypted payloads in image pixels, decrypt and XOR-deobfuscate them, then execute multi-stage backdoors (Denes and Remy variants). It documents two loader variants with anti-analysis and injection techniques, dissects the launcher, backdoor and C2 modules, and provides extensive IOCs (file hashes, embedded keys/IVs, C2 domains, registry paths), YARA rules and a Python decoder to aid detection and hunting.