OSX_OCEANLOTUS.D
S0352 · macOS
OSX_OCEANLOTUS.D is a macOS backdoor used by APT32. First discovered in 2015, APT32 has continued to make improvements using a plugin architecture to extend capabilities, specifically using .dylib files. OSX_OCEANLOTUS.D can also determine it's permission level and execute according to access type (root or user).
ATT&CK S0352
Sigma rules0
YARA rules0
Live IOCs0