The OceanLotus hacker group , widely known as APT32 , has launched a highly targeted surveillance campaign focused on China's "Xinchuang" IT ecosystem
See also: MuddyWater targets Turkey-Israel-Azerbaijan with UDPGangster Backdoor

This strategic shift focuses on intruding into domestically developed hardware and software, which are specifically designed to create secure and self-sufficient computing environments. By exploiting the unique architecture of these systems, attackers seek to penetrate sensitive government and industrial networks that were previously considered shielded from foreign cyberespionage.
The attackers use a flexible, multi-layered methodology, leveraging sophisticated spear-phishing baits tailored to the Linux architecture of Xinchuang terminals. These attack vectors include malicious .desktop (functioning similar to Windows shortcuts), PDF baits that retrieve remote documents via WPS Office, and JAR files that execute directly in pre-installed Java environments.
See also: Chinese hackers exploit VMware vCenter environments

These initial penetration methods, often disguised as official government announcements, are carefully designed to bypass standard security systems by interfering with legitimate administrative workflows and file formats commonly used by the sector. Blackorbird security analysts discovered the malware after observing a distinct pattern of supply chain breaches within the affected networks.
See also: CISA cites Chinese hackers using BRICKSTORM

Their research reveals that the group initially attempts to brute-force internal security servers before exploiting potential zero-day vulnerabilities to distribute malicious update scripts across the infrastructure.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
