Huntress threat hunters uncovered a multi-year intrusion (likely since 2017-2020) against a non-profit supporting Vietnamese human rights defenders, attributed with high confidence to APT32/OceanLotus. The attack used layered persistence mechanisms across four hosts including malicious scheduled tasks masquerading as Adobe/Microsoft services, COM object backdoors, DLL sideloading via legitimate executables (McAfee, Apple Software Update, Dropbox, calibre), Java JAR loaders, Node.js addons, and steganography hiding shellcode inside PNG files. The malware chain involved a patched iisutil.dll bloated above 50MB to evade YARA rules and sandbox file size limits, XOR-encrypted payloads, LZNT1 decompression, and Cobalt Strike beacons behind Cloudflare. SFTP-based C2 exfiltration, Chrome cookie theft, and domain masquerading were also observed. Infrastructure analysis confirmed Cobalt Strike team servers via unique Censys fingerprints. Over 15 technical overlaps with known APT32/OceanLotus TTPs were documented.

33m read timeFrom huntress.com
Post cover image
Table of contents
Executive SummaryBackgroundHunting MethodologyInvestigation and AnalysisSupporting AnalysisAnalysis of InfrastructureTargeting and AttributionIndicators of CompromiseMITRE ATT&CK Mapping