PHOREAL, also known as RIZZO, is a Windows backdoor associated with the Vietnam-aligned cyberespionage group APT32 (OceanLotus). It supports initial victim characterization and follow-on post-exploitation operations intended to compromise organizational data confidentiality. PHOREAL communicates with command-and-control infrastructure over ICMP, can create a reverse shell for interactive command execution, and modifies the Windows Registry to store its configuration. In a campaign targeting a Vietnamese financial-services institution, PHOREAL was loaded into private executable memory within a legitimate Microsoft-signed Windows process, reflecting an in-memory defense-evasion approach. APT32 has used PHOREAL in operations against organizations with interests in Vietnam, including public and private-sector entities.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During one investigation, APT32 was observed using a privilege escalation exploit (CVE-2016-7255) masquerading as a Windows hotfix.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
PHOREAL/RIZZO is a backdoor allowing initial victim characterization and follow-on post-exploitation operations to compromise the confidentiality of organizations’ data.
PHOREAL/RIZZO is a backdoor allowing initial victim characterization and follow-on post-exploitation operations to compromise the confidentiality of organizations’ data.
14 distinct techniques documented for this family, organized by ATT&CK tactic.
“the malicious macros created two named scheduled tasks as persistence mechanisms for two backdoors on the infected system.”
“delivered as a multi-stage PowerShell script… delivered as shellcode in a PowerShell script…”
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The analysis team "were able to extract an RC4 encrypted domain from an RCDATA resource"; the decrypted domain was thelivemusicgroup[.]com.
“installed one backdoor as a persistent service with a legitimate service name… Another backdoor used an otherwise legitimate DLL filename…”
"Anchor has used ICMP in C2 communications." / "COATHANGER uses ICMP for transmitting configuration information..." / "PHOREAL communicates via ICMP for C2." / "Regin ... can use ICMP to communicate between infected computers." / "Cobalt Strike can be configured to use TCP, ICMP, and UDP for C2 communications."
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware tool identified as part of OceanLotus's arsenal.
Backdoor used by OceanLotus that leverages ICMP for command-and-control communications.
An implant previously present on an overlapping victim environment tied to REF4322; mentioned as coexisting or preceding SPECTRALVIPER activity.
Previously observed implant on one endpoint in the REF4322 environment; it is mentioned as background to the subsequent SPECTRALVIPER infection.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.