logo

APT32__2019__OceanLotus_KerrDown.pdf

ID: a2780e0e-0749-4146-b72b-3963efdc603a

STIX ID: report--a2780e0e-0749-4146-b72b-3963efdc603a

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2019-03-15

Last Modified Date: 2019-03-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Unit42 details KerrDown, a custom downloader attributed to OceanLotus (APT32) used since at least early 2018 to deliver Cobalt Strike via base64-embedded DLLs in malicious Office documents and RAR archives that employ DLL sideloading; the report provides technical analysis, Jaccard-index similarity clustering, compile-time/timezone attribution, and numerous IoCs (file hashes and C2 domains).