OceanLotus: Extending Cyber Espionage Operations Through Fake Websites
ID: f896034b-589a-52f6-9138-d517deadcf72
STIX ID: report--f896034b-589a-52f6-9138-d517deadcf72
Feed Name: Volexity Blog
Threat Score
Volexity reports that the OceanLotus APT has created and operated numerous convincing fake news websites and Facebook pages to profile visitors, spear-phish targets, and deliver platform-specific malware—including a malicious DLL that loads a Cobalt Strike Beacon—using social-engineered fake video/Flash prompts and cloud-hosted payloads; the report provides technical details, decoded C2 configuration, and a comprehensive set of IOCs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
