1
Groups Using This
1
Platforms
166
Prevalence Rank
0
Known Aliases
Description

OSX_OCEANLOTUS.D is a macOS backdoor used by APT32. First discovered in 2015, APT32 has continued to make improvements using a plugin architecture to extend capabilities, specifically using `.dylib` files. OSX_OCEANLOTUS.D can also determine it's permission level and execute according to access type (`root` or `user`).

View MITRE record ↗

Platforms
macOS
Groups Deploying OSX_OCEANLOTUS.D (1)
↑