Denis is a Windows backdoor associated with APT32, also known as OceanLotus. It enables remote control of compromised computers and has variants implemented in PowerShell and deployed as memory-resident shellcode. Its discovery functions collect the victim's username and local IP address and query Windows Registry keys and values. It also supports commands to delete files. Denis Base64-encodes data sent to its command-and-control server and decrypts strings used for command-and-control communication during execution.
Denis uses process hollowing, dynamic Windows API resolution, and anti-debugging checks to hinder analysis and conceal execution. It has been loaded through DLL side-loading involving legitimate applications, including WPS word-processing software and Adobe 3D Utility. An observed OceanLotus deployment used a Vietnamese-language environmental-themed archive containing images and a malicious HTA script. The script decrypted an embedded loader and executed shellcode in memory, leading to a staged installation that launched Denis through side-loaded DLLs. This deployment established persistence through a Registry autorun entry and used host-derived installation names, execution-flow obfuscation, and inflated files to impede detection and analysis.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The loaded shellcode is a variant of the Denis family used by OceanLotus.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
The content repeatedly describes threat actors and malware using PowerShell to execute payloads, run commands, download additional malware, perform lateral movement, evade defenses, and execute scripts in memory. | Examples include: 'APT28 downloads and executes PowerShell scripts and performs PowerShell commands'; 'APT3 has used PowerShell on victim systems to download and run payloads after exploitation'; 'TA505 has used PowerShell to download and execute malware and reconnaissance scripts.'
Numerous entries state malware can create a remote shell or reverse shell, for example 4H RAT, BLACKCOFFEE, DarkComet, PlugX, QuasarRAT, and others. | The content repeatedly describes threat actors and malware using cmd.exe, the Windows command shell, to execute commands, launch payloads, run batch files, and automate actions on compromised hosts.
The content repeatedly describes malware and threat actors collecting the victim username, identifying logged-in users, running whoami, query user, quser, or similar commands to determine the current user or user sessions.
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, sw_vers -productVersion, and fsutil.
The content repeatedly describes malware and threat actors that can "download files from C2," "download additional payloads," "upload and download files," "retrieve payloads from the C2 server," and "copy files to remote machines."
3 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
44 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Backdoor used by OceanLotus that implements DNS tunneling for command-and-control communications.
Trojan that enumerates and collects the username from the victim machine.
Malware with a PowerShell-based variant.
Uses ipconfig to gather system IP addresses.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.