ATT&CKReferencesVolexity OceanLotus Nov 2017

Volexity OceanLotus Nov 2017

Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017.

Open the source

Techniques0

Not cited by any technique.

Groups1

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples3

TechniqueUsed byProcedure example
T1071.001
Web Protocols
GroupAPT32

APT32 has used JavaScript that communicates over HTTP or HTTPS to attacker controlled domains to download additional frameworks. The group has also used downloaded encrypted payloads over HTTP.

T1105
Ingress Tool Transfer
GroupAPT32

APT32 has added JavaScript to victim websites to download additional frameworks that profile and compromise website visitors.

T1505.003
Web Shell
GroupAPT32

APT32 has used Web shells to maintain access to victim websites.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.