OceanLotus, also known as APT32, is a Vietnam-linked cyber-espionage operation and associated set of modular backdoors. It has targeted government and corporate networks in East and Southeast Asia as well as journalists, dissidents, human-rights organizations, media entities, research organizations, and other targets perceived as politically sensitive to the Vietnamese state. Public reporting has associated the operation with extensive surveillance infrastructure, selective compromise of websites, and campaigns against Vietnamese and regional targets.
OceanLotus malware has targeted Windows and macOS, with code and command-and-control protocol similarities also linking the Linux RotaJakiro backdoor to the family. Delivery has included spearphishing attachments, document-themed double-extension lures, malicious application bundles masquerading as documents, and watering-hole compromises using repackaged or fake software installers. Windows infection chains have used staged droppers, encrypted payloads, in-memory PE loading, and DLL side-loading through legitimate signed executables. macOS variants have used deceptive application bundles, decoy documents, multistage payloads, and LaunchAgent or LaunchDaemon persistence.
OceanLotus backdoors provide host reconnaissance, encrypted command-and-control, file upload and download, file and directory operations, execution of commands or dynamically loaded modules, and deployment of additional components. Observed variants use custom encrypted protocols and fallback web-based communications. Defense-evasion features include obfuscated strings and payloads, deletion of intermediate artifacts, timestamp modification, masquerading, in-memory execution, and use of legitimate binaries for side-loading. Windows variants have established persistence through services and user-level startup mechanisms, while macOS variants use launchd-based persistence.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A few months ago, we discovered and analyzed one of their latest backdoors. Several tricks are being used to convince the user to execute the backdoor, to slow down its analysis and to avoid detection.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The string decode routine now consists of a combination of bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded.
Once the user has extracted the zip file, they see a directory containing a file with a Microsoft Word document icon. The file is actually an application bundle, which contains executable code. | The malware uses the decoy document to help mask the execution of the malware.
Not highlighted in Figure 11 but also included in this packet is the kernel boot time... Figure 11 shows ... en0 : AA:BB:CC:DD:EE:FF ... en0 : 192.168.1.254
The backdoor uses a custom binary protocol on TCP port 443, a well-known port that is unlikely to be blocked by traditional firewalls due to its use in HTTPS connections.
RotaJakiro and OceanLotus use separate data structures to hold C2 session information... C2 domain name resolution and session establishment are performed in one function.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware development trick 44: Stealing data via legit GitHub API. Simple C example. OceanLotus BitRAT RecordBreaker
A macOS (Mach-O) backdoor sample whose code and C2 protocol design are assessed as homologous to RotaJakiro. The sample supports C2 registration, device-information collection/upload, and plugin-based function execution.
A surveillance-focused malware/operations set tied in the article to spear-phishing, malicious news websites, credential theft, visitor profiling, inbox compromise, and spyware delivery against dissidents, journalists, media, and human rights targets.
A macOS backdoor delivered as a fake document app bundle inside a ZIP archive. It uses multi-stage payloads, establishes persistence via LaunchAgents, collects host information, communicates with C2 servers, and supports commands including file upload/download, command execution, and download-and-execute.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.