OCEANMAP

Malware updated 4 months ago (2024-05-04T21:17:36.080Z)
Download STIX
Preview STIX
OceanMap is a C#-based malware used by APT28, a Russia-linked group, as part of a sophisticated cyber attack campaign that started in 2020. The malware is designed to execute base64-encoded commands via cmd.exe, providing persistent and remote access to the targeted endpoint. Once a command is executed, OceanMap stores the results in the inbox directory, allowing APT28 to clandestinely monitor the attack and adjust its strategy accordingly. The APT28 group has targeted Ukrainian government entities and Polish organizations using phishing messages to deploy bespoke implants and information stealers such as MASEPIE, OCEANMAP, and STEELHOOK. In their latest campaign, they have used previously undetected malware like OCEANMAP to steal sensitive information from target networks. They also used it to upload data-stealing malware called Steelhook, which targets web browsers, and a backdoor called Oceanmap, which leverages email software. The Computer Emergency Response Team of Ukraine (CERT-UA) issued a warning about this new phishing campaign. One of the files downloaded to infected machines during these attacks is "Oceanmap," a tool for command execution via the Internet Message Access Protocol (IMAP). The original variant of OceanMap had information-stealing functionality, but this has since been transferred to another payload named "Steelhook," associated with the same campaign. This shift in tactics demonstrates the evolving nature of the threat posed by APT28.
Description last updated: 2024-05-04T20:49:59.695Z
What's your take? (Question 1 of 4)
Help tune the shared Cybergeist dataset, assist your peers, and earn karma. Expand the panel to get started.
Possible Aliases / Cluster overlaps
It's hard to track cluster overlaps and naming conventions between vendors, so here are some possible overlapping names / profiles you also may want to look at.
IDVotesProfile Description
Masepie
3
MASEPIE is a malicious software (malware) first discovered in December 2023, which is capable of establishing persistence on Windows machines and executing arbitrary commands. It is described as a small Python backdoor that enables the downloading and uploading of files. When victims click to view l
Steelhook
3
Steelhook is a malicious PowerShell script used by the Russia-linked Advanced Persistent Threat group, APT28, to steal sensitive information from compromised systems. The malware was discovered as part of a phishing campaign orchestrated by APT28, as reported by the Computer Emergency Response Team
Miscellaneous Associations
Other elements of context that could aid in the identification of relevance
Backdoor
Malware
Analyst Notes & Discussion
Be the first to leave your mark here! Log in to share your views and vote.
Associated Threat Actors
To see the evidence that has resulted in these threatActor associations, create a free account
IDTypeVotesProfile Description
APT28Unspecified
2
APT28, also known as Fancy Bear, Pawn Storm, Sofacy Group, Sednit, BlueDelta, and STRONTIUM, is a threat actor linked to Russia that has been active since at least 2007. The group has targeted governments, militaries, and security organizations worldwide, including the German Social Democratic Party
Source Document References
Information about the OCEANMAP Malware was read from the documents corpus below. This display is limited to 20 results, create a free account to see more
PreviewSource LinkCreatedAtTitle
CERT-EU
6 months ago
Russian hackers unleash sophisticated phishing campaigns across the globe
CERT-EU
8 months ago
Cyber Security Week In Review: December 29, 2023
BankInfoSecurity
8 months ago
Russian Military Intelligence Blamed for Blitzkrieg Hacks
CERT-EU
8 months ago
New malware found in analysis of Russian hacks on Ukraine, Poland | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting
Securityaffairs
8 months ago
Russia's APT28 used new malware in a recent phishing campaign
CERT-EU
8 months ago
CERT-UA Uncovers New Malware Wave Distributing OCEANMAP, MASEPIE, STEELHOOK
DARKReading
6 months ago
Russian Intelligence Targets Victims Worldwide in Rapid-Fire Cyberattacks
CERT-EU
6 months ago
APT28 Hacker Group Targeting Europe, Americas, Asia in Widespread Phishing Scheme | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #hacker | National Cyber Security Consulting