TF-MAL-osx.oceanlotus
📛 Threat Title
Malware family: OceanLotus
Description
ThreatFox malware family `osx.oceanlotus`. Printable name: OceanLotus.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
osx.oceanlotus
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.oceanlotus
IOC database
- Type
- domain
- Value
osx.oceanlotus- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-osx.oceanlotus
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/osx.oceanlotus
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:attack.mitre.org
ID: G0050 ⓘ Associated Groups: SeaLotus, OceanLotus , APT-C-00, Canvas Cyclone, BISMUTH Contributors: Romain Dumont, ESET Version: 3.0 Created: 14 December 2017
-
web:cipherssecurity.com
Kaspersky researchers attribute malicious PyPI packages delivering ZiChatBot malware to OceanLotus APT, using Zulip team chat REST APIs as covert command-and-control infrastructure.
-
web:jsis.washington.edu
The OceanLotus group, also known as APT32, is an offensive cybersecurity organization that has been known to conduct cyber intrusion and espionage campaigns since 2013 (Carr 2017). One of its earliest operations was captured by the digital rights organization, the Electronic Frontier Foundation (EFF), after staff members received phishing emails with malware that was traced back to the group ...
-
web:malpedia.caad.fkie.fraunhofer.de
Cyber espionage actors, now designated by FireEye as APT32 ( OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. FireEye assesses that APT32 leverages a unique suite of fully-featured malware , in conjunction with commercially-available tools, to conduct targeted ...
-
web:otx.alienvault.com
Cyber espionage actors, now designated by FireEye as APT32 ( OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. FireEye assesses that APT32 leverages a unique suite of fully-featured malware , in conjunction with commercially-available tools, to conduct targeted ...
-
web:securelist.com
Kaspersky researchers uncovered malicious wheel packages in PyPI that targeted both Windows and Linux and contained a dropper delivering malware dubbed ZiChatBot. We attribute this activity to OceanLotus APT.
-
web:www.antiy.net
This remote control payload is the RUST remote control malware long used by the OceanLotus organization. The attack processes closely resemble the OceanLotus organization's 2025 attack activities, with only minor variations in covert execution methods like MST conversion and DLL hijacking techniques.
-
web:www.infoseclabs.io
Effective mitigation involves regular web security audits, updating software, and implementing endpoint detection and response (EDR) systems. The True Story & Timeline Operation Ocean Lotus bears resemblance to real-world attacks conducted by APT32, also known as OceanLotus , which have been active since at least 2014.
-
web:www.researchgate.net
PDF | This presentation examines the activities of OceanLotus , a Vietnamese cyber-military threat group also known as APT32. The research further... | Find, read and cite all the research you need ...
-
web:www.securityscientist.net
APT32 (G0050), known as OceanLotus , is a Vietnamese APT targeting ASEAN governments, automotive firms, and journalists. Explore their custom malware , DNS C2, macOS tools, and defense strategies.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.