ESET reported that the OceanLotus threat group, also tracked as APT32 and APT-C-00, deployed an updated backdoor against company and government networks in East Asia. The intrusion chain relied on social-engineering lures, including double-extension decoy files and fake software installers such as RobototFontUpdate.exe, to deliver a multi-stage dropper and backdoor. The malware used layered obfuscation, encrypted payloads, and shellcode-based PE loading to hinder analysis and detection.
The campaign also abused DLL side-loading through legitimate signed executables, including Symantec’s rastlsc.exe, to execute malicious components while appearing trustworthy. After installation, the backdoor established persistence through a Windows service or Run registry key, then communicated with command-and-control servers over TCP port 25123 with fallback HTTP/HTTPS channels. ESET said the malware gave operators broad post-compromise access, including host fingerprinting, file and registry manipulation, process execution, and the ability to load additional payloads.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
ESET's March 2018 report analyzed an updated OceanLotus (APT32/APT-C-00) backdoor used against company and government networks in East Asia, including targets in Vietnam, the Philippines, Laos, and Cambodia. The report described delivery via malicious email attachments and fake installers, plus a multi-stage loader, DLL side-loading, persistence, and RC4-encrypted command-and-control communications.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.