
OceanLotus Hid Denis Backdoor Behind Forged Microsoft Identity and DNS Tunnel
Two Denis backdoor variants compiled in December 2015 impersonated Microsoft system binaries while routing command-and-control traffic through DNS NULL record queries to a pre-staged domain pair. The deployment combined a forged certificate chain, dynamic API resolution, and time-based sandbox evasion into a coherent doctrine of layered deception that kept its network infrastructure virtually undetected throughout its operational life.
Two Win32 executables compiled on the same December afternoon in 2015 represent something more instructive than their age might suggest: a precisely engineered deception stack in which every layer — binary identity, code-signing posture, execution behaviour, and network communications — was designed to pass as something legitimate. Both are Denis backdoor variants attributed to OceanLotus (also tracked as APT32, Canvas Cyclone, and Bismuth).
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read