logo

OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks

ID: 2b70eebb-698a-53c5-b001-39d28d8f12f1

STIX ID: report--2b70eebb-698a-53c5-b001-39d28d8f12f1

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-08

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

APT32 (OceanLotus) has launched a targeted surveillance campaign against China's Xinchuang IT ecosystem, using tailored spear-phishing (malicious .desktop files, JAR lures, weaponized EPUBs) and supply-chain techniques to exploit Atril Document Viewer (CVE-2023-52076) and deploy persistent, encrypted payloads and a Python-based downloader for long-term access and data exfiltration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.