ATT&CKReferencesVolexity Ocean Lotus November 2020

Volexity Ocean Lotus November 2020

Adair, S. and Lancaster, T. (2020, November 6). OceanLotus: Extending Cyber Espionage Operations Through Fake Websites. Retrieved November 20, 2020.

Open the source

Techniques2

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1036.005
Match Legitimate Resource Name or Location
GroupAPT32

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

T1059.007
JavaScript
GroupAPT32

APT32 has used JavaScript for drive-by downloads and C2 communications.

T1102
Web Service
GroupAPT32

APT32 has used Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1189
Drive-by Compromise
GroupAPT32

APT32 has infected victims by tricking them into visiting compromised watering hole websites.

T1204.001
Malicious Link
GroupAPT32

APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails.

T1566.002
Spearphishing Link
GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

T1583.001
Domains
GroupAPT32

APT32 has set up and operated websites to gather information and deliver malware.

T1583.006
Web Services
GroupAPT32

APT32 has set up Dropbox, Amazon S3, and Google Drive to host malicious downloads.

T1585.001
Social Media Accounts
GroupAPT32

APT32 has set up Facebook pages in tandem with fake websites.

T1598.003
Spearphishing Link
GroupAPT32

APT32 has used malicious links to direct users to web pages designed to harvest credentials.

T1608.001
Upload Malware
GroupAPT32

APT32 has hosted malicious payloads in Dropbox, Amazon S3, and Google Drive for use during targeting.

T1608.004
Drive-by Target
GroupAPT32

APT32 has stood up websites containing numerous articles and content scraped from the Internet to make them appear legitimate, but some of these pages include malicious JavaScript to profile the potential victim or infect them via a fake software update.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.