OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks
ID: 2b70eebb-698a-53c5-b001-39d28d8f12f1
STIX ID: report--2b70eebb-698a-53c5-b001-39d28d8f12f1
Feed Name: cybersecurityNews.com
Threat Score
APT32 (OceanLotus) has launched a targeted surveillance campaign against China's Xinchuang IT ecosystem, using tailored spear-phishing (malicious .desktop files, JAR lures, weaponized EPUBs) and supply-chain techniques to exploit Atril Document Viewer (CVE-2023-52076) and deploy persistent, encrypted payloads and a Python-based downloader for long-term access and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
