PHOREAL Malware Targets the Southeast Asian Financial Sector
ID: 9f95342d-dbe6-5d84-b964-3aa6e8901194
STIX ID: report--9f95342d-dbe6-5d84-b964-3aa6e8901194
Feed Name: Elastic Security Labs
Elastic Security detected a targeted campaign (REF4322) attributed to APT32 (OceanLotus) using the PHOREAL/RIZZO in-memory backdoor against a Vietnamese financial services organization. Analysts observed shellcode_thread memory protection alerts on control.exe, identified an unsigned tscon32.dll with matching PHOREAL artifacts, extracted an RC4-encrypted C2 domain (thelivemusicgroup.com -> 103.75.117.250) and a DLL SHA256, and produced a YARA rule and mitigation guidance to detect and block the activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
