APT32__2019__OceanLotus_KerrDown.pdf
ID: a2780e0e-0749-4146-b72b-3963efdc603a
STIX ID: report--a2780e0e-0749-4146-b72b-3963efdc603a
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2019-03-15
Last Modified Date: 2019-03-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
**Executive Summary:** Unit42 details KerrDown, a custom downloader attributed to OceanLotus (APT32) used since at least early 2018 to deliver Cobalt Strike via base64-embedded DLLs in malicious Office documents and RAR archives that employ DLL sideloading; the report provides technical analysis, Jaccard-index similarity clustering, compile-time/timezone attribution, and numerous IoCs (file hashes and C2 domains).
