APT32__2019__OceanLotus.pdf
ID: ec851d3d-e9ef-4eba-8528-f509cecac607
STIX ID: report--ec851d3d-e9ef-4eba-8528-f509cecac607
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2019-06-21
Last Modified Date: 2019-06-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
QiAnXin Threat Intelligence Center analyzes an OceanLotus attack targeting a Vietnamese environmentalist: an obfuscated HTA (cactusTorch) carries appended encrypted data that loads a .NET-based Loader (L.dll) which XOR-decodes and executes shellcode in memory. The chain uses DLL side-loading with a legitimate executable (rasman.exe) and malicious companion DLLs (CoolType.dll loads rasman.db3 shellcode — a Denis-family variant), creates persistence via registry Run keys, drops a decoy DOCX, and communicates with C2 udt.sophiahoule.com; the report includes IOCs (file hashes, C2) and detailed TTPs for detection and mitigation.
