Netskope Threat Labs

OceanLotus

ATP Sandbox Adv. HeuristicsAV

OceanLotus is a backdoor that targets macOS computers, and its operators have used it against human rights and media organizations, research institutes, and maritime construction companies. It spreads through fake Adobe Flash Player installers and malicious Word documents, with the documents likely distributed through malspam emails.

First seen
March 2022
Last seen
October 2026
Oceanlotus
Alert Name
Linux.Trojan.OceanLotus
MacOS.Trojan.OceanLotus
Trojan.Linux.OceanLotus.1
Trojan.Linux.OceanLotus.2
Trojan.Linux.OceanLotus.3
Trojan.MAC.OceanLotus.A
Trojan.MAC.OceanLotus.E
Win32.Backdoor.Oceanlotus
Win32.Trojan.Oceanlotus
Win32.Trojan.OceanLotus