OSX_OCEANLOTUS.D is a macOS backdoor associated with OceanLotus, also tracked as APT32, SeaLotus, and Cobalt Kitty. It has been used in targeted espionage activity against organizations including human rights groups, media organizations, research institutes, and maritime-related entities. The malware is delivered through malicious Microsoft Word lure documents that prompt users to enable macros; the macro logic extracts and launches an additional payload that installs the backdoor on macOS systems.
The malware chain includes a dropper that deploys the final backdoor, selects installation locations based on privilege level, and establishes persistence through macOS launch items. Persistence has been observed via LaunchAgents, and related reporting also notes LaunchDaemon use when running with elevated privileges. The installer hides the deployed payload, modifies timestamps for defense evasion, starts the backdoor, and removes the dropper and related installation artifacts after execution.
OSX_OCEANLOTUS.D performs host profiling prior to command-and-control communications. Observed collection includes system details such as operating system version, username, computer name, architecture, and host-derived identifiers including the network interface MAC address. Communications use encrypted and encoded data handling, including compressed custom TCP protocol traffic in some variants.
As a remote-access backdoor, it supports command execution and file operations on compromised hosts. Documented capabilities include uploading files from the victim system, deleting files, loading dynamic libraries, and executing follow-on functionality delivered by the operator. Variants have also used packing and scripting components, including PowerShell and Perl during execution and installation stages. Overall, OSX_OCEANLOTUS.D is a macOS espionage backdoor focused on persistence, host reconnaissance, stealth, and operator-controlled post-compromise access.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
We identified a MacOS backdoor (detected by Trend Micro as OSX_OCEANLOTUS.D) that we believe is the latest version of a threat used by OceanLotus... The dropper is used to install the backdoor into the infected system and establish its persistence.
22 distinct techniques documented for this family, organized by ATT&CK tactic.
AppleSeed has the ability to execute its payload via PowerShell... APT19 used PowerShell commands to execute payloads... APT28 downloads and executes PowerShell scripts and performs PowerShell commands... Start-Process / Invoke-Command / System.Management.Automation
The content repeatedly describes payloads, strings, configuration files, scripts, URLs, and binaries being obfuscated or encoded using Base64, XOR, RC4, AES, RSA, hex encoding, custom algorithms, and other methods across many malware families and threat actors.
It extracts theme0.xml file from the Word document. theme0.xml is a Mach-O 32-bit executable... For root user path: /Library/CoreMediaIO/Plug-Ins/FCP-DAL/iOSScreenCapture.plugin/Contents/Resources/ processname: screenassistantd For regular user path: ~/Library/Spelling/ processname: spellagentd
The app bundle is disguised as a doc file to trick users into executing it
The content repeatedly describes malware and threat actors deleting files, directories, droppers, logs, scripts, temporary files, exfiltrated archives, and uninstalling themselves to cover tracks or reduce forensic artifacts.
APT28 has performed timestomping on victim files. APT29 has used timestomping to alter the Standard Information timestamps on their web shells to match other files in the same directory. APT32 has used scheduled task raw XML with a backdated timestamp... APT38 has modified data timestamps to mimic files that are in the same folder on a compromised host.
AdFind can extract subnet information from Active Directory; actors used ipconfig /all, netsh.exe, ifconfig, arp, route, nbtstat, and related APIs/commands to gather IP, MAC, DNS, DHCP, gateway, proxy, routing, ARP, and adapter information.
Running getpwuid ->pw_name, scutil --get ComputerName, and uname –m will provide the following returns respectively: Mac OSX 10.12. System Administrator <owner’s name>'s iMac x86_64
The content repeatedly describes malware and threat actors collecting OS version, computer name, architecture, CPU, memory, disk, BIOS, language, and other host details; examples include use of commands such as ver, systeminfo, hostname, uname -m, and WMI to gather host information.
Andariel has collected large numbers of files from compromised network systems for later extraction... APT28 has retrieved internal documents from machines inside victim environments... BADNEWS crawls the victim's local drives and collects documents... many listed groups and malware collect files, documents, credentials, payment card data, or other information from compromised hosts.
Some Backdoor.Oldrea samples use standard Base64 + bzip2... gh0st RAT has used Zlib to compress C2 communications data before encrypting it... HOPLIGHT has utilized Zlib compression to obfuscate the communications payload.
The content is a long ATT&CK-style listing showing numerous malware families and threat groups that 'use HTTP,' 'use HTTPS,' 'HTTP POST requests,' 'HTTP GET requests,' or 'HTTP/S' for command and control communications. | Specific implementations mentioned include 'HTTP POST requests,' 'HTTP GET requests,' 'custom HTTP cookies,' 'Cookie HTTP header,' 'HTTP Upgrade request' for WebSocket initiation, and use of APIs such as 'Microsoft Graph API' or 'Dropbox HTTP API' for C2.
Like older versions of the OceanLotus backdoor, the new version contains two main functions: one for collecting operating system information and submitting this to its malicious C&C servers and receiving additional C&C communication information, and another for the backdoor capabilities.
37 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A custom macOS backdoor associated with OceanLotus/APT32, noted for multi-layered persistence.
macOS malware referenced as using LoginHook-based persistence on macOS.
macOS malware that uses the touch -t command to alter timestamps.
Uses Word macros for execution.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.