{
  "family": "oceanlotus",
  "sample_count": 1,
  "category": "backdoor",
  "description": "<h3>Executive Summary</h3>\nOceanLotus (also widely known as APT32 or Canvas Assassin) is a highly sophisticated Advanced Persistent Threat (APT) group believed to be aligned with the state interests of Vietnam. Active since at least 2013, OceanLotus conducts targeted cyber espionage campaigns against foreign corporations (particularly in the manufacturing, consumer products, and hospitality sectors), foreign governments, dissidents, and journalists.\n\n<h3>Infection Vector and Technical Capabilities</h3>\nOceanLotus relies heavily on highly targeted, culturally specific spear-phishing campaigns containing weaponized attachments (often utilizing CVE-2017-11882) or strategic web compromises (Watering Hole attacks) to gain initial access.\n\nTheir toolset is highly customized and evinces a deep understanding of multiple operating systems:\n<ul>\n<li><strong>Cross-Platform Capabilities:</strong> OceanLotus is unique in its deployment of sophisticated backdoors tailored for both Windows and macOS environments. Their macOS malware is often disguised as legitimate software installers or documents.</li>\n<li><strong>Custom Backdoors (Cobalt Strike & Custom Implants):</strong> The group frequently utilizes heavily obfuscated variants of Cobalt Strike alongside custom-built, multi-stage backdoors (like Windshield or Denis) designed for long-term espionage, file exfiltration, and lateral movement.</li>\n<li><strong>Evasion and Obfuscation:</strong> The group employs advanced evasion techniques, including deep shellcode obfuscation, in-memory execution, Steganography (hiding payloads in image files), and utilizing legitimate cloud services (like Google Drive) for C2 communication to bypass network perimeter defenses.</li>\n</ul>\n\n<h3>Threat Assessment</h3>\nDetection of OceanLotus (APT32) activity is a critical, \"glass break\" security incident. It indicates that the organization is actively being targeted by a well-resourced, highly skilled nation-state actor focused on long-term intellectual property theft and surveillance.\n\n<h3>Incident Response and Remediation</h3>\n<ul>\n<li><strong>Assume Broad Compromise:</strong> Due to the advanced nature of the threat actor, incident responders must assume that initial access on a single endpoint has already resulted in lateral movement and credential theft across the Active Directory environment.</li>\n<li><strong>Hunt for Anomalies (EDR):</strong> Traditional AV is insufficient. Responders must utilize EDR telemetry to hunt for specific OceanLotus behaviors: anomalous PowerShell execution, `mshta.exe` abuse, unauthorized scheduled tasks, and C2 beacons to cloud infrastructure.</li>\n<li><strong>Coordinated Eviction:</strong> Eradication requires a highly coordinated, enterprise-wide effort to simultaneously sever C2 channels, reset all domain credentials, and rebuild compromised infrastructure to prevent the actor from re-establishing persistence.</li>\n</ul>",
  "cta": "Published by the SystemHelpdesk team.",
  "aliases": [
    "APT32",
    "Canvas Assassin",
    "SeaLotus"
  ],
  "enrichment_level": "insufficient_information",
  "faq": [],
  "faq_count": 0,
  "mitre_attack": [
    "T1566.001",
    "T1059.001",
    "T1132.001",
    "T1105"
  ],
  "cisa_advisory": null,
  "last_updated": "2026-07-01T17:35:12Z",
  "type": "APT Group / Backdoor",
  "target_industries": [
    "Global / Opportunistic"
  ],
  "motivation": "Opportunistic",
  "threat_actors": [
    "Unknown / Cybercriminal"
  ],
  "target_geographies": [
    "Global"
  ]
}