Rewterz
Rewterz Threat Advisory – ICS: ICONICS and Mitsubishi Electric HMI SCADA
January 21, 2022
Rewterz
Rewterz Threat Advisory – SolarWinds Serv-U Vulnerability Exploited in the Wild
January 21, 2022

Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs

Severity

High

Analysis Summary

Cyber espionage actors, aka APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. APT32 leverages a unique suite of fully-featured malware, in conjunction with commercially available tools, to conduct targeted operations that are aligned with Vietnamese state interests. In their current campaign, APT32 has leveraged files that employ social engineering methods to entice the victim into enabling macros. Upon execution, the initialized file downloads multiple malicious payloads from remote servers. APT32 actors continue to deliver malicious attachments via spear-phishing emails. APT32 actors designed multilingual lure documents which were tailored to specific victims. Although the files had “.DRV” file extensions, the recovered phishing lures were web page archives that contained text and images.

Impact

  • Information Theft and Espionage
  • Data exfiltration

Indicators of Compromise

Filename

  • UClientStartup[.]dll

MD5

  • 7dcd84e04d6467ddb33a7752874494eb

SHA-256

  • fe007fdca5608656ff35c198b0e3f33fd722e0ee3a2993b41cbbcef49e74f11d

SHA-1

  • d622dbd4004b17152c1469434c8dcf85b0a5e2f2

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on links/ attachments sent by unknown senders.