Researchers reported that the Vietnam-linked APT32/OceanLotus group deployed a multi-stage macOS backdoor inside an application bundle disguised as a Microsoft Word document. The lure used a hidden Unicode character and a bait-and-switch technique to display a legitimate decoy document while silently dropping additional payloads. SentinelLabs linked the activity to earlier OceanLotus macOS operations previously documented by Trend Micro, indicating continued investment by the group in Apple-focused intrusion tooling.
The first-stage shell script carried a large base64-encoded Mach-O payload, removed quarantine attributes, and attempted to bypass macOS App Translocation before launching later stages. The malware then established persistence through a hidden LaunchAgent or LaunchDaemon named com.apple.marcoagent.voiceinstallerd, and the final stage enabled backdoor functions including host profiling, file download, and data exfiltration. Researchers said the malware also borrowed stealth ideas seen in coin-miner tradecraft, while exposing huntable artifacts such as hard-coded identifiers, code-signing details, file paths, hashes, C2 domains, and noisy anti-quarantine behavior; Apple has since revoked the observed code signatures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
SentinelLabs published analysis of an updated multi-stage macOS backdoor attributed to APT32/OceanLotus, describing its disguised Word-document delivery, LaunchAgent/LaunchDaemon persistence, and third-stage backdoor capabilities.
Microsoft published analysis describing how the threat actor used coin-miner-style techniques to remain under the radar, adding technical detail on the campaign’s evasion tradecraft.
Trend Micro published research on a new macOS backdoor connected to the OceanLotus/APT32 threat group, documenting the malware family later discussed by other vendors.
Palo Alto Networks Unit 42 published research on an improved macOS OceanLotus backdoor targeting victims in Vietnam, detailing its fake Word-document delivery, LaunchAgent/LaunchDaemon persistence, and encrypted custom C2 protocol. The report also noted the operation was still active as recently as early June 2017 and included indicators of compromise.
Palo Alto Networks Unit 42 published research on the 'Komplex' OS X trojan attributed to Sofacy, documenting a separate macOS malware development from the OceanLotus/APT32 activity in the existing timeline.
Apple revoked the code-signing certificates associated with the observed APT32 macOS malware samples, disrupting trust in the identified binaries.
AlienVault published research on OceanLotus malware for OS X distributed as an application bundle pretending to be an Adobe Flash update, adding an earlier public technical disclosure of the group's macOS tooling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcemicrosoft.com
Open sourcetrendmicro.com
Open sourceresearchcenter.paloaltonetworks.com
Open sourceblog.paloaltonetworks.com
Open sourcedeveloper.apple.com
Open sourcealienvault.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.