Overview 547 indicators
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
| domain | 501 | G0050-domain.txt |
| ipv4 | 27 | G0050.json |
| url | 13 | G0050.json |
| url_path | 6 | G0050.json |
Techniques 78 ATT&CK
Open in ATT&CK Navigator → or download the layer (78 techniques, layer 4.5)
- T1003 OS Credential Dumping
- T1003.001 LSASS Memory
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1021.002 SMB/Windows Admin Shares
- T1027.010 Command Obfuscation
- T1027.011 Fileless Storage
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1033 System Owner/User Discovery
- T1036 Masquerading
- T1036.003 Rename Legitimate Utilities
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1055 Process Injection
- T1056.001 Keylogging
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1068 Exploitation for Privilege Escalation
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1071.003 Mail Protocols
- T1072 Software Deployment Tools
- T1078.003 Local Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1102 Web Service
- T1105 Ingress Tool Transfer
- T1112 Modify Registry
- T1135 Network Share Discovery
- T1137 Office Application Startup
- T1189 Drive-by Compromise
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1216.001 PubPrn
- T1218.005 Mshta
- T1218.010 Regsvr32
- T1218.011 Rundll32
- T1222.002 Linux and Mac Permissions
- T1505.003 Web Shell
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1550.002 Pass the Hash
- T1550.003 Pass the Ticket
- T1552.002 Credentials in Registry
- T1560 Archive Collected Data
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1564.004 NTFS File Attributes
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1569.002 Service Execution
- T1570 Lateral Tool Transfer
- T1571 Non-Standard Port
- T1574.001 DLL
- T1583.001 Domains
- T1583.006 Web Services
- T1585.001 Social Media Accounts
- T1588.002 Tool
- T1589 Gather Victim Identity Information
- T1589.002 Email Addresses
- T1598.003 Spearphishing Link
- T1608.001 Upload Malware
- T1608.004 Drive-by Target
- T1685.005 Clear Windows Event Logs
Software 15
- Mimikatz
- Net
- Arp
- ipconfig
- netsh
- Cobalt Strike
- WINDSHIELD
- KOMPROGO
- SOUNDBITE
- PHOREAL
- OSX_OCEANLOTUS.D
- Denis
- Goopy
- Kerrdown
- RotaJakiro
Principal sources 193 reports
Ranked by how many of this actor's indicators each report brought in.
- 62github.com/eset/malware-ioc/tree/master/oceanlotus
- 61x.com/ThreatBookLabs/status/18664955872746417…
- 46fireeye.com/blog/threat-research/2017/05/cyber-espi…
- 41securelist.com/apt-phantomlance/96772
- 41otx.alienvault.com/pulse/5ea84bfc21271700b46efeee
- 29volexity.com/blog/2020/11/06/oceanlotus-extending-cy…
- 29otx.alienvault.com/pulse/5fa570762d4ac937ddf1fdbe
- 25blackberry.com/content/dam/blackberry-com/asset/enterp…
Related groups 6
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 547 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 547. Complete: G0050.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/skocherhan/status/2080796885774680487 · virustotal.com/gui/file/d1cdeea8a081397632c0522476da21…
0b3l1sk.me -
x.com/blackorbird/status/2079936188832723190 · mp.weixin.qq.com/s/FIDg23u6Peb_cR8N7ddzbA · virustotal.com/gui/ip-address/211.4.0.204/relations
agoras.hopto.org agoras.zapto.org erp.manitec.ch manitec.ch -
x.com/phatomcandle/status/2069843016844738849
185.161.208.105:8080 185.161.208.105:8888 -
welivesecurity.com/en/eset-research/oceanlotus-external-es…
coachcybersecurity.com financemachinelearning.com gatewayrvcenter.com leadingfilipinoteams.com mxprodesign.com -
x.com/RedDrip7/status/2044239571370815802 · virustotal.com/gui/file/31e812704e41e7e779d96a553500d4…
152.32.144.5:443 -
x.com/blackorbird/status/1968961523323183313 · mp.weixin.qq.com/s/zZVmDDWHQx7XuJZ8YO6joA · virustotal.com/gui/file/88a67b1b0875495b30e93ec925908e…
ipv4 144.202.46.221:443 url http://46.37.124.147 -
x.com/ginkgo_g/status/1948568231582568853 · virustotal.com/gui/file/52ba0fd4b275a8e817dd5896534c51…
http://194.87.240.39 -
x.com/ThreatBookLabs/status/18772636512513928… · threatbook.io/blog/id/1100
ipv4 154.93.37.106:443 ipv4 178.255.220.115:443 ipv4 190.211.254.203:4443 ipv4 193.138.195.192:8443 ipv4 45.41.204.18:8443 url http://38.54.59.112 -
x.com/ThreatBookLabs/status/18664955872746417…
andreafaerber.com benjamiilliams.club benjamiilliams.icu colingrovesjama.com deraller.com earlase.com groveskekwiciv.com imberly.com mesarigna.com ndreafaeraphael.com ns1.andreafaerber.com ns1.benjamiilliams.club ns1.benjamiilliams.icu ns1.colingrovesjama.com ns1.deraller.com ns1.earlase.com ns1.groveskekwiciv.com ns1.imberly.com ns1.mesarigna.com ns1.ndreafaeraphael.com ns1.ochefort.com ns1.odyluet.com ns1.philipppropst.icu ns1.radeordaunt.com ns1.rcheterre.com ns1.rieuenc.com ns1.roveskekwjascd.com ns1.ryeisasw.com ns1.urielcallum.com ns1.willipropst.icu ns2.andreafaerber.com ns2.benjamiilliams.club ns2.benjamiilliams.icu ns2.colingrovesjama.com ns2.deraller.com ns2.earlase.com ns2.groveskekwiciv.com ns2.imberly.com ns2.mesarigna.com ns2.ndreafaeraphael.com ns2.ochefort.com ns2.odyluet.com ns2.philipppropst.icu ns2.radeordaunt.com ns2.rcheterre.com ns2.rieuenc.com ns2.roveskekwjascd.com ns2.ryeisasw.com ns2.urielcallum.com ns2.willipropst.icu ochefort.com odyluet.com philipppropst.icu radeordaunt.com rcheterre.com rieuenc.com roveskekwjascd.com ryeisasw.com urielcallum.com willipropst.icu -
x.com/banthisguy9349/status/18759852097469194…
alyerrac.com annamerrett.com audreybourgeois.com feieraagsbend.com houseoasa.com lginstree.com oftonlos.com rigitteais.com shawnabuddicom.com spencerday.com ugdale.com vieoulden.com -
x.com/ThreatBookLabs/status/18664955872746417…
45.41.204.15:443 -
x.com/blackorbird/status/1863941553494135219
103.91.67.74:4443 -
x.com/blackorbird/status/1861408316561465675
jieyitongweb.com -
x.com/blackorbird/status/1839213152036331887 · mp.weixin.qq.com/s/YFT0Bx4Suph5yCv6OQiHzA · virustotal.com/gui/file/d83c86431777714878e7ccd93f479b… · virustotal.com/gui/file/578a366c15308da2c6c2bb02eafef8… · virustotal.com/gui/file/af50f57eed423ce82e82c857bbdf3e… · virustotal.com/gui/file/acf0fb4dac33e197de3a3e142eeaa7… · virustotal.com/gui/file/c961b128c9ecab3aad2b91d4c1b33f… · virustotal.com/gui/file/958fdf608a9c166177c5cfa024f51d…
http://64.176.58.16 -
x.com/blackorbird/status/1839213152036331887 · mp.weixin.qq.com/s/YFT0Bx4Suph5yCv6OQiHzA · virustotal.com/gui/file/d83c86431777714878e7ccd93f479b… · virustotal.com/gui/file/578a366c15308da2c6c2bb02eafef8… · virustotal.com/gui/file/af50f57eed423ce82e82c857bbdf3e… · virustotal.com/gui/file/acf0fb4dac33e197de3a3e142eeaa7… · virustotal.com/gui/file/c961b128c9ecab3aad2b91d4c1b33f… · virustotal.com/gui/file/958fdf608a9c166177c5cfa024f51d…
strengthening-memories-reports-restoration.trycloudflare.com -
x.com/liqingjia1989/status/1836348262665912781 · search.censys.io/hosts/109.107.171.113 · virustotal.com/gui/file/3ca75ac0393ef0f6ec5bf3add09523…
ipv4 109.107.171.113:22 ipv4 109.107.171.113:443 ipv4 109.107.171.113:51821 url http://109.107.171.113 -
x.com/blackorbird/status/1829074866135532011 · huntress.com/blog/advanced-persistent-threat-targeti…
domain adobe.riceaub.com domain base.msteamsapi.com domain blank.eatherurg.com domain cdn.arlialter.com domain cds55.lax8.setalz.com domain dupbleanalytics.net domain fbcn.enantor.com domain get.dupbleanalytics.net domain hx-in-f211.popfan.org domain kpi.msccloudapp.com domain msccloudapp.com domain msteamsapi.com domain priv.manuelleake.com domain var.alieras.com domain ww1.erabend.com ipv4 185.198.57.184:8888 ipv4 185.43.220.188:8888 -
x.com/wa1Ile/status/1793822326938829288 · virustotal.com/gui/file/e0b176aa8d4496adef17b4a698a848…
http://139.180.201.211 -
x.com/liqingjia1989/status/1808401108731417012 · virustotal.com/gui/file/f6270624e606ec0768b6821cada234… · virustotal.com/gui/file/f197ee22e964192080d6c5e2b4deff…
http://27.0.232.169 -
twitter.com/liqingjia1989/status/1779688782989808055 · virustotal.com/gui/ip-address/179.43.151.13/relations · virustotal.com/gui/file/13a1b25c8f9cbb3771e694945fbcfc…
dfizm.com ecom.dfizm.com -
twitter.com/liqingjia1989/status/1777517072492478907 · virustotal.com/gui/file/14515bc33a3e6c8f8cafae1598a1ea…
guilty-patricia-connecticut-pulled.trycloudflare.com -
twitter.com/liqingjia1989/status/1752140516081475763 · virustotal.com/gui/file/be2648d8ac9aca8c1fb338328dccdf…
160.86.38.21:443 -
twitter.com/RexorVc0/status/1730499792575299950 · mp.weixin.qq.com/s/IB2w86cXcpmGS8qrOnprKw?ref=www.ctfiot… · virustotal.com/gui/file/acf612349fb6ee5d88e2a7da3d39af…
http://161.129.34.132 -
securelist.com/apt-phantomlance/96772 · otx.alienvault.com/pulse/5ea84bfc21271700b46efeee
jaxonsorensen.club kristianfiedler.club -
virustotal.com/gui/file/1bd7ad55c5615169706676cd266f52…
msofficecloud.org -
twitter.com/ThreatBookLabs/status/16650308972200960…
sints.infonetcorporation.org -
twitter.com/ThreatBookLabs/status/16391001381856870…
185.82.126.4:8888 -
twitter.com/SethKingHi/status/1626502575225999360 · virustotal.com/gui/file/bdf6614cde566b3cca10544729e870… · virustotal.com/gui/file/4199f09978ac8f433f2e554826386b…
shortjuvenilebuttons.koobphee.repl.co -
twitter.com/ThreatBookLabs/status/15931996528072458… · virustotal.com/gui/file/3a299afeefbe200504b09d168c2210… · virustotal.com/gui/file/4701084d836ad99f10ca0b17ff49ec… · virustotal.com/gui/file/6d901a0ef4e4357aef1bc4919b681c… · virustotal.com/gui/file/741a5533378a3d071ed9029ab0d619… · virustotal.com/gui/file/98541970bf7e1de78100bf40add332… · virustotal.com/gui/file/fcdd52dd47846377c434056121137c…
zabbixasaservice.com -
elfdigest.com/brief/19f16a4eceb8b57b2bcad11c76446f05b… · virustotal.com/gui/file/19f16a4eceb8b57b2bcad11c76446f…
imap.jxycnews.com jxycnews.com -
twitter.com/blackorbird/status/1587712368901251072 · mp.weixin.qq.com/s/v2wiJe-YPG0ng87ffBB9FQ (Chinese)
eu-draytek.com -
twitter.com/JAMESWT_MHT/status/1551531206038196225
sugary-tough-time.glitch.me -
github.com/blackorbird/APT_REPORT/blob/master/Ocea… · virustotal.com/gui/file/66b58b2afd274591fb8caf2dbfcf14…
http://86.105.18.241 -
twitter.com/pancak3lullz/status/1486817995418750979
screeching-lavish-riverbed.glitch.me smooth-talented-runner.glitch.me -
twitter.com/blackorbird/status/1481527529475559427 · netskope.com/blog/abusing-microsoft-office-using-mal… · github.com/netskopeoss/NetskopeThreatLabsIOCs/tree…
confusion-cerulean-samba.glitch.me elemental-future-cheetah.glitch.me torpid-resisted-sugar.glitch.me -
twitter.com/RedDrip7/status/1430098641528647681 · virustotal.com/gui/file/bbb84b90e0a90e614b2a46542b576f… · virustotal.com/gui/file/8ccd9591e9438a313a21958c7f8edc…
chart.expocasheuro.com expocasheuro.com -
github.com/ti-research-io/ti/blob/main/ioc_extende…
km170.com -
twitter.com/BaoshengbinCumt/status/1465923917793554…
url http://5.255.86.129 url http://5.79.75.210 url http://83.149.110.52 url_path /M70uojiYNua5Hx4UYxUMahnmS45He2 -
twitter.com/blackorbird/status/1471443630506201090 · mp.weixin.qq.com/s/ZpU27cCSKa14aupNcCHcug
gifted-boulder-transport.glitch.me river-cliff-crate.glitch.me -
twitter.com/ShadowChasing1/status/14207644366424965… · twitter.com/tonydoublezero/status/14210468825754664… · virustotal.com/gui/file/b87c090e422e96f332bcfac4ef3dc5… · twitter.com/blackorbird/status/1471443630506201090 · mp.weixin.qq.com/s/ZpU27cCSKa14aupNcCHcug
cooperative-supreme-pisces.glitch.me -
twitter.com/360CoreSec/status/1414520646436999171 · virustotal.com/gui/file/3ec9ba9732737f75168c22c14815de… · virustotal.com/gui/file/af68d1a0208dff0240c959996664b7… · virustotal.com/gui/file/5eb715cfaaf1f325c4431e9bfc12db…
domain sjbingdu.info ipv4 185.225.19.100:443 ipv4 221.219.213.178:8081 -
twitter.com/ShadowChasing1/status/13975605279293071… · virustotal.com/gui/domain/kginfocom.com/relations · virustotal.com/gui/file/489fca69a622195328302e64e29b61…
infodocs.kginfocom.com kginfocom.com ousync.kginfocom.com -
twitter.com/ShadowChasing1/status/13970572439467745… · virustotal.com/gui/domain/dinefilly.com/detection · virustotal.com/gui/file/c2abe7c37c2fb5ac50b1039bb03f3b…
dinefilly.com -
twitter.com/ShadowChasing1/status/13970572439467745… · virustotal.com/gui/domain/dinefilly.com/detection · virustotal.com/gui/file/c2abe7c37c2fb5ac50b1039bb03f3b…
tintuc.dinefilly.com -
twitter.com/360Netlab/status/1390297734981246978 · blog.netlab.360.com/stealth_rotajakiro_backdoor_en · blog.netlab.360.com/rotajakiro_linux_version_of_oceanlotus
eduelects.com mirror-codes.net sublineover.net thaprior.net -
twitter.com/360Netlab/status/1390297734981246978 · blog.netlab.360.com/stealth_rotajakiro_backdoor_en · blog.netlab.360.com/rotajakiro_linux_version_of_oceanlotus
blog.eduelects.com cdn.mirror-codes.net news.thaprior.net status.sublineover.net -
twitter.com/ShadowChasing1/status/13700030715608637… · virustotal.com/gui/file/aa331051db461ff1dc760616f23770…
services.serveftp.net -
amnesty.org/en/latest/research/2021/02/click-and-ba… · github.com/AmnestyTech/investigations/tree/master/… · otx.alienvault.com/pulse/603d189d3e938ff6555b68c8
api.ciscofreak.com art.guillermoespana.com land.rellecharlessper.com tips.jasperpfeiffer.com -
amnesty.org/en/latest/research/2021/02/click-and-ba… · github.com/AmnestyTech/investigations/tree/master/… · otx.alienvault.com/pulse/603d189d3e938ff6555b68c8
coco.cechire.com delicalo.dnsalias.net -
twitter.com/ShadowChasing1/status/13970572439467745… · virustotal.com/gui/domain/dinefilly.com/detection · virustotal.com/gui/file/c2abe7c37c2fb5ac50b1039bb03f3b…
dangky.dinefilly.com -
twitter.com/ShadowChasing1/status/13558661807292456… · twitter.com/ShadowChasing1/status/13558713331926343… · virustotal.com/gui/file/f0a05aaed382f667c49f74f005a754…
apiservice.webhop.net -
twitter.com/GroupIB_GIB/status/1338816922687770624 · twitter.com/GroupIB_GIB/status/1338817396069593088 · virustotal.com/gui/ip-address/45.61.139.211/relations
domain cbo.group ipv4 45.61.139.211:443 -
twitter.com/blackorbird/status/1337225399177150464
facebookdeck.com -
twitter.com/virusbtn/status/1333383787737214977 · trendmicro.com/en_us/research/20/k/new-macos-backdoor-… · otx.alienvault.com/pulse/5fc69d3770679c907b87aea3
idtpl.org mihannevis.com mykessef.com -
volexity.com/blog/2020/11/06/oceanlotus-extending-cy… · otx.alienvault.com/pulse/5fa570762d4ac937ddf1fdbe
arbenha.com baodachieu.com baomoivietnam.com dance-til-dawn.podzone.net fontloading.com gservice.reviews gusercontent.com hmacount.com hypepodscase.com khmer-livenews.com khmerleaks.com kmernews.com laostimenews.com laotiantimes.com ledanvietnam.org malaynews.org nhansudaihoi13.org outlook-client.com philiippinesnews.net serrvice.net thamcungbisu.org theme.blogwix.com tinmoivietnam.com tinmoivietnam.net tocaoonline.org viewerservice.com yhsetting.com -
twitter.com/ShadowChasing1/status/13234386872967905… · virustotal.com/gui/file/133e629b27bae2309ca9fd39a78b07…
clouds.onthewifi.com -
twitter.com/ShadowChasing1/status/13213200090548715… · virustotal.com/gui/file/68cfaca326fd8953be4a3ece8161c3…
45.63.123.237:46405 -
twitter.com/ShadowChasing1/status/13192381632278159… · virustotal.com/gui/file/47ba92dc8c9302b2f70db70a0d46fe…
domain bussinesappinstant.com domain cloud.bussinesappinstant.com ipv4 43.254.132.117:46405 -
twitter.com/ShadowChasing1/status/13184992241708523… · virustotal.com/gui/file/a030435018a67c07747751766132eb…
domain dns.insappstaticanalyze.com domain insappstaticanalyze.com ipv4 43.254.132.212:46405 -
amnesty.org/en/latest/research/2021/02/click-and-ba… · github.com/AmnestyTech/investigations/tree/master/… · otx.alienvault.com/pulse/603d189d3e938ff6555b68c8
node.podzone.org -
twitter.com/ShadowChasing1/status/13156792277573058… · twitter.com/ShadowChasing1/status/13156834639833661…
bucket.serveftp.net gacha.knowsitall.info -
blog.malwarebytes.com/malwarebytes-news/2020/10/kraken-attack… · otx.alienvault.com/pulse/5f7c8a82c21d00312155d28a
asia-kotoba.net yourrighttocompensation.com -
twitter.com/ccxsaber/status/1277183467889942528 · twitter.com/Arkbird_SOLG/status/1312380799514284032 · app.any.run/tasks/2a8d467c-65e4-417f-a747-b6e59bf03… · virustotal.com/gui/file/dbde2b710bee38eb3ff1a72b673f75…
tripplekill.mentosfontcmb.com -
twitter.com/ShadowChasing1/status/12962499695070699… · app.any.run/tasks/92bbc70b-02a6-4b4d-bbb0-2a4922ef2… · virustotal.com/gui/file/ffaf7e81f2334fd2e1ccc21d6b861c…
beautifull-font.salebusinesend.com -
twitter.com/ShadowChasing1/status/12962499695070699… · app.any.run/tasks/92bbc70b-02a6-4b4d-bbb0-2a4922ef2… · virustotal.com/gui/file/ffaf7e81f2334fd2e1ccc21d6b861c…
domain salebusinesend.com ipv4 202.59.10.170:46405 -
twitter.com/ShadowChasing1/status/12895025589484912… · virustotal.com/gui/file/3547f3e8f7c5aec3f507d75e7d3d25…
feeder.blogdns.com -
twitter.com/batrix20/status/1289066669109780480 · virustotal.com/gui/file/86cebd189cfdcfb6e76cba7a258d7f… · virustotal.com/gui/file/7709b376ea5b388e1b415a93fc618c…
accounts.getmyip.com -
twitter.com/ccxsaber/status/1277183467889942528 · twitter.com/Arkbird_SOLG/status/1312380799514284032 · app.any.run/tasks/2a8d467c-65e4-417f-a747-b6e59bf03… · virustotal.com/gui/file/dbde2b710bee38eb3ff1a72b673f75…
mentosfontcmb.com -
twitter.com/cyber__sloth/status/1272470254141288450
domain systeminfor.com url http://167.88.180.198 -
twitter.com/ShadowChasing1/status/12682005265643438… · volexity.com/blog/2020/11/06/oceanlotus-extending-cy… · otx.alienvault.com/pulse/5fa570762d4ac937ddf1fdbe
summerevent.webhop.net -
twitter.com/ShadowChasing1/status/12576154285887324…
letsme.gotdns.com -
securelist.com/apt-phantomlance/96772 · otx.alienvault.com/pulse/5ea84bfc21271700b46efeee
anaehler.com anofrio.com api.anaehler.com bit.catalinabonami.com cyn.ettebiermahalet.com egg.stralisemariegar.com file.log4jv.info hr.halettebiermann.com log.osloger.biz log4jv.info mine.remaariegarcia.com news.sqllitlever.info osloger.biz paste.christienollmache.xyz sqllitlever.info staff.kristianfiedler.club us.jaxonsorensen.club viodger.com -
fireeye.com/blog/threat-research/2020/04/apt32-targ… · otx.alienvault.com/pulse/5ea052d6cc299691b6ed1480
inquirerjs.com libjss.inquirerjs.com m.topiccore.com topiccore.com -
blackberry.com/content/dam/blackberry-com/asset/enterp… · securelist.com/apt-phantomlance/96772 · otx.alienvault.com/pulse/5ea84bfc21271700b46efeee
aki.viperse.com cloud.anofrio.com game2015.net inc.graceneufville.com itpk.mostmkru.com ming.chujong.com mokkha.goongnam.com nhaccuatui.android.zyngacdn.com quam.viperse.com sadma.knrowz.com taiphanmemfacebookmoi.info term.ursulapaulet.com video.viodger.com -
blackberry.com/content/dam/blackberry-com/asset/enterp…
art.yfieldrainasch.com doc.rainaschiffer.com fp.rentwoylas.com gameandroid.taiphanmemfacebookmoi.info heal.lancebarkerwa.com science.tayenthflores.com status.elizongham.com traits.senapusmireault.com ulse.chujong.com wand.gasharontomholt.com -
app.any.run/tasks/b3612ff4-c8b2-409d-98d4-77c64c8a0… · fireeye.com/blog/threat-research/2020/04/apt32-targ… · otx.alienvault.com/pulse/5ea052d6cc299691b6ed1480
vitlescaux.com -
twitter.com/ESETresearch/status/1208032053108850688 · otx.alienvault.com/pulse/5e063be1a6ed30bd243f100e
opengroup.homeunix.org -
twitter.com/pancak3lullz/status/1204059496005488642
bmw-corp.net bmwthailand.org h61.p.ctrader.com huyndai-auto.com netsy.trutanner.com raffesla.idfnv.net -
twitter.com/pancak3lullz/status/1204065037448613889
auth.lineage2ez.com -
otx.alienvault.com/pulse/5de9067483d85294ef9e77b4
360skylar.host ad.ssageevrenue.com baidu-search.net cdnwebmedia.com clip.shangweidesign.com news.shangrilaexports.com sys.genevrebreinl.com tel.caitlynwells.com upgrade.coldriverhardware.com us.melvillepitcairn.com
Further reading 198
- attack.mitre.org/groups/G0050
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- amnestyusa.org/wp-content/uploads/2021/02/Click-and-Ba…
- cybereason.com/blog/operation-cobalt-kitty-apt
- fireeye.com/blog/threat-research/2017/05/cyber-espi…
- volexity.com/blog/2017/11/06/oceanlotus-blossoms-mas…
- welivesecurity.com/2018/03/13/oceanlotus-ships-new-backdoor
- welivesecurity.com/2019/03/20/fake-or-fake-keeping-up-with…
- twitter.com/ccxsaber/status/1277183467889942528
- blackberry.com/content/dam/blackberry-com/asset/enterp…
- welivesecurity.com/en/eset-research/oceanlotus-external-es…
- github.com/netskopeoss/NetskopeThreatLabsIOCs/tree…
- twitter.com/pancak3lullz/status/1486817995418750979
- securelist.com/apt-phantomlance/96772
- virustotal.com/gui/file/19f16a4eceb8b57b2bcad11c76446f…
- github.com/AmnestyTech/investigations/tree/master/…
- twitter.com/ShadowChasing1/status/12576154285887324…
- twitter.com/Arkbird_SOLG/status/1157319751238131717
- twitter.com/ShadowChasing1/status/12962499695070699…
- virustotal.com/gui/file/fcdd52dd47846377c434056121137c…
- google.com/search?q=%22jessicajoshua.com%22
- x.com/blackorbird/status/1863941553494135219
- virustotal.com/gui/ip-address/45.61.139.211/relations
- mp.weixin.qq.com/s/zZVmDDWHQx7XuJZ8YO6joA
- amnesty.org/en/latest/research/2021/02/click-and-ba…
- virustotal.com/gui/file/741a5533378a3d071ed9029ab0d619…
- twitter.com/cyber__sloth/status/1272470254141288450
- search.censys.io/hosts/109.107.171.113
- twitter.com/blackorbird/status/1108687601475555328
- twitter.com/ThreatBookLabs/status/16391001381856870…
- virustotal.com/gui/file/af68d1a0208dff0240c959996664b7…
- twitter.com/blackorbird/status/1113328823947264001
- twitter.com/GroupIB_GIB/status/1338817396069593088
- app.any.run/tasks/b3612ff4-c8b2-409d-98d4-77c64c8a0…
- x.com/blackorbird/status/1839213152036331887
- virustotal.com/gui/file/4701084d836ad99f10ca0b17ff49ec…
- twitter.com/ESETresearch/status/1208032053108850688
- twitter.com/ShadowChasing1/status/13156792277573058…
- twitter.com/ShadowChasing1/status/13156834639833661…
- virustotal.com/gui/file/be2648d8ac9aca8c1fb338328dccdf…
158 more, and the report behind every indicator, in G0050.json.