OceanSalt is a malware family and associated intrusion activity cluster known for using spearphishing emails with malicious Microsoft Office attachments as an initial access vector. The malware has process discovery capability and can collect the names and identifiers of running processes on an infected system, indicating host reconnaissance and post-compromise situational awareness. Based on the available facts, OceanSalt is associated with phishing-led compromise and local process enumeration, but there is insufficient high-confidence information here to attribute it to a specific country, define broader victimology, or characterize additional capabilities such as persistence, lateral movement, or data exfiltration.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Enumerates running processes including process names and PIDs as host reconnaissance.
Spearphishing using Microsoft Office attachments to deliver payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.