216.73.216.6

Suspected APT-C-00 Delivers Havoc Trojan

· Published 22/09/2025 08:11 · Modified 22/09/2025 20:12

Export JSON

Essential information

Published
22/09/2025 08:11
Modified
22/09/2025 20:12
Tags
2025-09-22 apt dll sideloading east asia havoc rat persistence process-hollowing trojan
Related entities
1 intrusion sets (apt), 4 techniques (mitre), 1 malware, 1 others

Description

A recent analysis of a suspicious loader reveals similarities to the -C-00 (Ocean Lotus) group, a government-backed hacker organization targeting East Asian companies and government agencies. The sample, a DLL file with excellent evasion capabilities, uses hash algorithms to dynamically obtain API functions. It creates a mutex for single-instance execution, validates command-line parameters, adds itself to the registry for , and sets up a VEH exception handler. The loader employs module hollowing to replace code in certmgr.dll with shellcode that reflectively loads the . The tactics and development environment align with Ocean Lotus' known techniques, including the use of Mingw-w64 and similar initialization processes.

External references