SOUNDBITE is a malware family associated with the Vietnam-aligned threat actor APT32, also known as OceanLotus. FireEye/Mandiant describes it as one of APT32’s signature malware payloads, alongside WINDSHIELD, KOMPROGO, and PHOREAL, and observed it in targeted intrusions against private-sector organizations including consumer products companies operating in or connected to Vietnam. The content also notes OceanLotus has used SOUNDBITE among its broader espionage tooling.
Based on the provided references, SOUNDBITE is a Windows malware/backdoor capable of modifying the Windows Registry, including storing backdoor configuration data there, and of enumerating application windows. These behaviors are consistent with host discovery and configuration/persistence support. The content does not provide a fuller standalone technical profile, specific infection chain, or unique indicators of compromise for SOUNDBITE itself, but places it within APT32/OceanLotus spear-phishing-led operations that used malicious ActiveMime ".mht" lure documents disguised as ".doc" files to entice victims to enable macros and download multiple payloads. Reported APT32 targeting includes foreign corporations tied to Vietnam’s manufacturing, consumer products, and hospitality sectors, as well as foreign governments, dissidents, journalists, and diaspora-related targets. No SOUNDBITE-specific hashes, filenames, registry paths, or network indicators are directly provided in the content.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 CVE Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.
During one investigation, APT32 was observed using a privilege escalation exploit (CVE-2016-7255) masquerading as a Windows hotfix.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Some of the key tools in its arsenal include SOUNDBITE (aka Denis), PHOREAL (aka Rizzo), WINDSHIELD (aka Remy), and, more recently, SPECTRALVIPER...
10 distinct techniques documented for this family, organized by ATT&CK tactic.
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
During the 2015 Ukraine Electric Power Attack, Sandworm Team modified in-registry Internet settings to lower internet security before launching rundll32.exe ... AADInternals can modify registry keys ... ADVSTORESHELL is capable of setting and deleting Registry values ... [many additional examples].
Multiple malware families are described as identifying/enumerating open windows or capturing foreground window titles (e.g., via EnumWindows, GetForegroundWindow, GetWindowText) to understand user activity and provide context for keylogging/screencapture.
The content is a long ATT&CK-style listing of malware and threat actors that collect host details such as OS version, hostname, architecture, CPU, memory, BIOS, language, and other basic system characteristics; examples include use of commands like systeminfo, ver, uname, sw_vers, and WMI queries.
The content repeatedly describes malware and threat actors listing files and directories, enumerating drives, searching for files by extension/name/path, retrieving file metadata, and browsing file systems (for example: "APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection" and "cmd can be used to find files and directories with native functionality such as dir commands").
61 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware tool identified as part of OceanLotus's arsenal.
Backdoor using DNS for C2, with process creation, file upload, shell command execution, file/directory and registry manipulation, window enumeration, and system information gathering.
Backdoor capable of modifying the Registry.
Malware capable of modifying the Windows Registry.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.