Tuesday 28 July 2026 15:24:06 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

Cyber Intelligence & Threat Trends

Vietnam’s OceanLotus Infiltrates China’s Xinchuang Tech: APT32’s Linux Pivot Exposed

Published: 08 December 2025 10:47Category: Cyber Intelligence & Threat TrendsGeo: AsiaAuthor: NEXUSGUARDIAN

State-backed hackers are targeting China’s domestic IT ecosystem with cutting-edge spear-phishing and supply chain attacks, marking a bold expansion into new digital territory.

In a cyber-espionage twist worthy of a spy thriller, the notorious OceanLotus group-also known as APT32-has set its sights on China’s Xinchuang technology ecosystem. Once infamous for targeting Windows systems across Southeast Asia, OceanLotus is now adapting its toolkit to infiltrate China’s homegrown hardware and software platforms, raising alarm bells across Asia’s cybersecurity landscape.

Inside the Xinchuang Offensive

Security researchers have tracked a series of calculated cyberattacks throughout 2025, with OceanLotus leveraging spear-phishing campaigns that mimic official Chinese policy documents and industry notices. The group’s lures-ranging from fake .desktop shortcuts and Java (.jar) executables to weaponized PDF files-are tailored to blend seamlessly into the Xinchuang environment, targeting both government and enterprise users.

One standout tactic involves malicious .desktop files, the Linux equivalent of Windows shortcuts. When unsuspecting users open a file like “Notice on Printing and Distributing the Minutes of the 2025 Meeting of the Energy Industry Shale Gas Standardization Technical Committee.pdf.desktop,” hidden commands execute in the background, launching persistent channels for command-and-control (C2) communications.

OceanLotus has also capitalized on the widespread use of Java in Chinese ICT infrastructure. Bait files such as “The Path Dispute of the Asia-Pacific Free Trade Area and China’s Plan.jar” install advanced downloaders after verifying the system environment, a move reflecting the group’s technical sophistication and adaptability.

In a bold technical leap, the hackers exploited CVE-2023-52076-a critical bug in the Atril Document Viewer, common in Linux MATE desktops. By distributing a malicious EPUB file, they managed to embed persistent, encrypted Python downloaders and autostart scripts, ensuring long-term access to compromised machines.

Supply Chain Intrusions: The Next Front

Beyond phishing, OceanLotus is now attacking the internal supply chains of Xinchuang-based networks. After gaining a foothold, the group conducted month-long reconnaissance missions, followed by brute-force attacks and the exploitation of yet-unknown vulnerabilities to push malicious software updates. This approach allows them to compromise entire networks from within, escalating their impact far beyond individual victims.

The group’s pivot to Linux and domestically curated Chinese platforms signals a significant evolution in their strategy-one that could have ripple effects for supply chain security and IT sovereignty across the region.

As China doubles down on technological self-reliance, OceanLotus’s campaign is a stark reminder: when digital borders rise, so too do the ambitions of cyber adversaries. The battle for control over emerging tech ecosystems has only just begun.

Glossary (WIKICROOK)

Spear-phishing
A targeted email attack designed to trick specific individuals into revealing sensitive information or installing malware.
Supply Chain Attack
A cyberattack that targets less secure elements in a supply network to compromise the entire system.
.desktop File
A type of shortcut file used in Linux environments to launch applications or commands, similar to Windows .lnk files.
Command-and-Control (C2)
Infrastructure used by attackers to remotely control compromised systems and exfiltrate data.
Persistence
Techniques used by attackers to maintain long-term access to a compromised system even after reboots or security updates.