logo

OceanLotus Continues With Its Cyber Espionage Operations

ID: 147db718-a5c3-595e-8162-12d62255c165

STIX ID: report--147db718-a5c3-595e-8162-12d62255c165

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-05-09

Date Updated: 2026-07-16

...
...

OceanLotus (APT3) conducted a targeted watering-hole campaign delivering a malicious RAR named Adobe_Flash_Install.rar that contained a legitimate Google updater executable which side‑loads a packed goopdate.dll; the DLL decodes configuration strings, fetches and executes a Cobalt Strike stager (noted C2 summerevent.webhop.net), and exfiltrates system/browser data. Cyble's analysis includes technical indicators (SHA-256 hashes), network captures, and behavioral details to support detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.