OSX_OCEANLOTUS.D — Malware Profile

OSX_OCEANLOTUS.D is a macOS backdoor used by APT32. First discovered in 2015, APT32 has continued to make improvements using a plugin architecture to extend capabilities, specifically using `.dylib` files. OSX_OCEANLOTUS.D can also determine it's permission level and execute according to access type (`root` or `user`).

MITRE ATT&CK techniques (28)

Attributed threat actors

Read the full analysis on IntelFusions