OceanLotus, also tracked as APT32, is a malware ecosystem and intrusion set associated with a Vietnamese-speaking threat actor known for cyber-espionage and surveillance operations. Its tooling includes multi-stage Windows and macOS backdoors used against government and corporate networks in East and Southeast Asia, as well as journalists, dissidents, human rights organizations, media entities, and other targets viewed as politically or strategically significant. Reported victimology has included organizations and individuals in Vietnam, the Philippines, Laos, Cambodia, and broader regional and international civil-society and media communities.
On Windows, OceanLotus has used socially engineered droppers delivered through spearphishing attachments, double-extension decoy executables, fake document icons, malicious document-based lures, and watering-hole style fake installers. Observed tradecraft includes encrypted and compressed multi-stage payload chains, shellcode-based in-memory PE loading, anti-analysis measures, decoy document display, and DLL sideloading through legitimate signed executables. Persistence has been established either as a service when elevated privileges are available or through user autorun mechanisms when not. Backdoor functionality has included host fingerprinting, file and registry operations, process execution, loading of additional components, and encrypted command-and-control over custom TCP as well as fallback HTTP/HTTPS channels with proxy support.
On macOS, OceanLotus has deployed advanced backdoors disguised as document files or application bundles embedded in archive files. These variants have used decoy Word documents, filename masquerading, staged payload extraction, quarantine attribute removal, timestomping, self-deletion, and persistence via LaunchAgents or LaunchDaemons. macOS samples have supported host reconnaissance, file transfer, file and directory deletion, terminal command execution, and modular extension through dynamically loaded libraries. Command-and-control traffic has used custom binary protocols with compression and symmetric encryption.
OceanLotus operations have also been linked to malicious websites, fake news or activist-themed sites, and selective malware delivery based on visitor profiling. The actor has used spearphishing and watering-hole techniques to identify, track, and compromise targets, and has combined bespoke malware with other offensive tooling such as Cobalt Strike. Across platforms, the malware family is characterized by strong defense evasion, modular post-compromise capability, and sustained espionage-oriented targeting.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
A few months ago, we discovered and analyzed one of their latest backdoors. Several tricks are being used to convince the user to execute the backdoor, to slow down its analysis and to avoid detection.
18 distinct techniques documented for this family, organized by ATT&CK tactic.
The string decode routine now consists of a combination of bit shifting and XOR operations with a variable key that depends on the length of the string that was encoded.
Once the user has extracted the zip file, they see a directory containing a file with a Microsoft Word document icon. The file is actually an application bundle, which contains executable code. | The malware uses the decoy document to help mask the execution of the malware.
Not highlighted in Figure 11 but also included in this packet is the kernel boot time... Figure 11 shows ... en0 : AA:BB:CC:DD:EE:FF ... en0 : 192.168.1.254
The client gathers all the data seen in Figure 11... username
The backdoor uses a custom binary protocol on TCP port 443, a well-known port that is unlikely to be blocked by traditional firewalls due to its use in HTTPS connections.
11 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware development trick 44: Stealing data via legit GitHub API. Simple C example. OceanLotus BitRAT RecordBreaker
A surveillance-focused malware/operations set tied in the article to spear-phishing, malicious news websites, credential theft, visitor profiling, inbox compromise, and spyware delivery against dissidents, journalists, media, and human rights targets.
A macOS backdoor delivered as a fake document app bundle inside a ZIP archive. It uses multi-stage payloads, establishes persistence via LaunchAgents, collects host information, communicates with C2 servers, and supports commands including file upload/download, command execution, and download-and-execute.
Referenced in APT32/OceanLotus macro-document samples that create scheduled tasks and use regsvr32/scrobj.dll to retrieve and execute an initial backdoor payload.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.