Qi An Xin Threat Intelligence Center reported that OceanLotus bactivity has increased since 2021.
This threat actor is excellent at mapping and surveying the whole network before and during attacks.
In 2022, the actor invaded Internet of Things (IoT) devices in an area with the purpose of using it as a platform to carry attacks on a different area.
This threat actor is resourceful, having access to multiple 0-day and n-day vulnerabilities to carry out its campaigns.
After a successful Intrusion, the tool tinyPortMapper is deployed to forward high-port traffic of the compromised IOT devices to the Cobalt Strike C2 Server, where the attacker orchestrates the attack.
It then tries to upload a busybox or dropbear to the IoT devices to facilitate further compromise.
Finally, OceanLotus deployed a Linux Trojan named Caja based on ARM, x86, and MIPS that are cross-compiled based on a set of source code and communication protocols.