logo

OceanLotus: Extending Cyber Espionage Operations Through Fake Websites

ID: f896034b-589a-52f6-9138-d517deadcf72

STIX ID: report--f896034b-589a-52f6-9138-d517deadcf72

Feed Name: Volexity Blog

Threat Score
85/100

Date Published: 2020-11-06

Date Updated: 2026-05-01

...
...

Volexity reports that the OceanLotus APT has created and operated numerous convincing fake news websites and Facebook pages to profile visitors, spear-phish targets, and deliver platform-specific malware—including a malicious DLL that loads a Cobalt Strike Beacon—using social-engineered fake video/Flash prompts and cloud-hosted payloads; the report provides technical details, decoded C2 configuration, and a comprehensive set of IOCs for detection and mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.