WINDSHIELD is a Windows backdoor associated with the Vietnam-aligned espionage group APT32, also known as OceanLotus. It has been identified as one of the group’s signature malware families alongside PHOREAL and SOUNDBITE, and has been used in targeted intrusions against organizations including entities in network security, banking, consumer products, and other sectors of strategic interest to Vietnam-linked operations.
Observed WINDSHIELD functionality includes host profiling and local system interaction. It can collect the current victim username, query Windows Registry values to gather system information, and interact with the file system, including deleting files. Its command-and-control communications have been observed using raw TCP sockets, and reporting has noted an unusual proxy-bypass mechanism in the malware’s networking design. These behaviors are consistent with post-compromise reconnaissance, operational flexibility in restricted network environments, and defense-evasion through artifact removal.
WINDSHIELD has been deployed as part of broader APT32 intrusion activity that frequently relied on targeted spearphishing and custom malware chains. In public reporting on APT32 operations, the family appears as a recurring payload in campaigns directed at both private-sector and political targets. The malware’s role within that ecosystem is that of a persistent remote-access capability used to profile victims, support operator control, and maintain access on compromised Windows systems.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During one investigation, APT32 was observed using a privilege escalation exploit (CVE-2016-7255) masquerading as a Windows hotfix.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its well-known tools include Denis (aka SOUNDBITE)... PHOREAL... WINDSHIELD, which features an interesting proxy bypass mechanism...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“the malicious macros created two named scheduled tasks as persistence mechanisms for two backdoors on the infected system.”
“delivered as a multi-stage PowerShell script… delivered as shellcode in a PowerShell script…”
“installed one backdoor as a persistent service with a legitimate service name… Another backdoor used an otherwise legitimate DLL filename…”
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting host details such as hostname, OS version, architecture, CPU, memory, BIOS, language, and other machine characteristics; e.g., "Action RAT has the ability to collect the hostname, OS version, and OS architecture of an infected host."
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware tool identified as part of OceanLotus's arsenal.
Backdoor/tool used by OceanLotus that features a proxy bypass mechanism.
Backdoor that can gather the victim username.
Gathers the victim username.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.