logo

APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

ID: f83d980b-4d63-54d0-8184-aa440dd21d44

STIX ID: report--f83d980b-4d63-54d0-8184-aa440dd21d44

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2025-01-09

Date Updated: 2026-04-22

Author: Divya

...
...

ThreatBook attributes a targeted supply-chain campaign to OceanLotus (APT32) in which a backdoored Cobalt Strike plugin and a malicious Visual Studio project (.suo) were published on GitHub to compromise Chinese cybersecurity professionals; the malware uses DLL hollowing, base64 encoding, and Notion for C2, exfiltrates data/identities, and ThreatBook published IOCs and detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.