WINDSHIELD is a malware family associated with the Vietnam-aligned threat actor APT32, also known as OceanLotus. Reporting describes it as one of APT32’s signature malware payloads and also refers to it by the alias Remy. High-confidence behaviors directly mentioned in the source material include gathering Windows Registry values, collecting the victim user name, deleting files and interacting with the file system, and communicating command-and-control traffic over raw TCP sockets. The content also notes that WINDSHIELD features a proxy bypass mechanism. Campaign reporting places WINDSHIELD in APT32 operations targeting multiple sectors and geographies, including Vietnam network security targets in 2014, Vietnam banking targets in 2016, and a United States consumer products target in 2016; broader APT32 reporting ties the group to intrusions against private-sector companies, foreign governments, dissidents, journalists, and organizations with business interests in Vietnam. The source material further states that APT32 commonly deployed WINDSHIELD alongside other tools such as KOMPROGO, SOUNDBITE (Denis), PHOREAL (Rizzo), and later SPECTRALVIPER.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During one investigation, APT32 was observed using a privilege escalation exploit (CVE-2016-7255) masquerading as a Windows hotfix.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Its well-known tools include Denis (aka SOUNDBITE)... PHOREAL... WINDSHIELD, which features an interesting proxy bypass mechanism...
13 distinct techniques documented for this family, organized by ATT&CK tactic.
“the malicious macros created two named scheduled tasks as persistence mechanisms for two backdoors on the infected system.”
“delivered as a multi-stage PowerShell script… delivered as shellcode in a PowerShell script…”
“installed one backdoor as a persistent service with a legitimate service name… Another backdoor used an otherwise legitimate DLL filename…”
The content repeatedly describes malware and threat actors querying, enumerating, opening, and reading Windows Registry keys and values, e.g., "APT41 queried registry values to determine items such as configured RDP ports and network configurations" and "Reg may be used to gather details from the Windows Registry of a local or remote system at the command-line interface."
The content repeatedly describes malware and threat actors collecting usernames, identifying logged-in users, running whoami/query user/quser, checking whether the current user is an administrator, enumerating user sessions, and gathering account details from compromised hosts.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware tool identified as part of OceanLotus's arsenal.
Backdoor/tool used by OceanLotus that features a proxy bypass mechanism.
Malware that gathers values from the Windows Registry.
Malware that gathers values from the Windows Registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.