

Rewterz Threat Alert – Microsoft Outlook Web Phishing
December 1, 2020
Rewterz Threat Alert – REvil Ransomware Returns with Gootkit Malware
December 1, 2020
Rewterz Threat Alert – Microsoft Outlook Web Phishing
December 1, 2020
Rewterz Threat Alert – REvil Ransomware Returns with Gootkit Malware
December 1, 2020Severity
High
Analysis Summary
APT 32, also known as OceanLotus is a Vietnamese state sponsored backed group and has emerged with a new malware targeting MacOS users with the motivation for espionage to aid Vietnamese-owned companies. The MacOS backdoor provides the attackers with a window into the compromised machine, enabling them to snoop on and steal confidential information and sensitive business documents
Attack Chain
The attacks begin with phishing emails that attempt to encourage victims to run a Zip file disguised as a Word document. It evades detection from antivirus scanners by using special characters deep inside a series of Zip folders. The attack could potentially give itself away if users are paying attention because, when the malicious file is run, a Microsoft Word document doesn’t appear. At this stage an initial payload is already working on the machine and it changes access permissions in order to load a second-stage payload that then prompts the installation of a third-stage payload, which downloads the backdoor onto the system. By installing the malware across different stages like this, OceanLotus aims to evade detection.
Impact
- Credential theft
- Data/ Information theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- ecffbd1687bacaf5f766c92097435f14
- be43be21355fb5cc086da7cee667d6e7
- e8a588b4a8ac95d4295b3bea94229131
SHA-256
- cfa3d506361920f9e1db9d8324dfbb3a9c79723e702d70c3dc8f51825c171420
- 48e3609f543ea4a8de0c9375fa665ceb6d2dfc0085ee90fa22ffaced0c770c4f
- 05e5ba08be06f2d0e2da294de4c559ca33c4c28534919e5f2f6fc51aed4956e3
SHA1
- c2e0b35fd4f24e9e98319e10c6f2f803b01ec3f1
- 48b4a87782e7c861b678d069d340aba4599a7d3e
- 9f84502cb44b82415bcf2b2564963613bdce1917
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Run and apply security patches to updated versions.