FILEMembers
FILE

OceanLotus Hid Denis Backdoor Behind Forged Microsoft Identity and DNS Tunnel

Two Denis backdoor variants compiled in December 2015 impersonated Microsoft system binaries while routing command-and-control traffic through DNS NULL record queries to a pre-staged domain pair. The deployment combined a forged certificate chain, dynamic API resolution, and time-based sandbox evasion into a coherent doctrine of layered deception that kept its network infrastructure virtually undetected throughout its operational life.

Jun 11, 2026, 19:41 (UTC+9)Last seenJun 11, 2026Severity72ByCTX TeamActorOceanLotusAPT32IOC4MITRE12RegionsCN

Two Win32 executables compiled on the same December afternoon in 2015 represent something more instructive than their age might suggest: a precisely engineered deception stack in which every layer — binary identity, code-signing posture, execution behaviour, and network communications — was designed to pass as something legitimate. Both are Denis backdoor variants attributed to OceanLotus (also tracked as APT32, Canvas Cyclone, and Bismuth).

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence