Vietnam’s OceanLotus Infiltrates China’s Xinchuang Tech: APT32’s Linux Pivot Exposed
State-backed hackers are targeting China’s domestic IT ecosystem with cutting-edge spear-phishing and supply chain attacks, marking a bold expansion into new digital territory.
In a cyber-espionage twist worthy of a spy thriller, the notorious OceanLotus group-also known as APT32-has set its sights on China’s Xinchuang technology ecosystem. Once infamous for targeting Windows systems across Southeast Asia, OceanLotus is now adapting its toolkit to infiltrate China’s homegrown hardware and software platforms, raising alarm bells across Asia’s cybersecurity landscape.
Inside the Xinchuang Offensive
Security researchers have tracked a series of calculated cyberattacks throughout 2025, with OceanLotus leveraging spear-phishing campaigns that mimic official Chinese policy documents and industry notices. The group’s lures-ranging from fake .desktop shortcuts and Java (.jar) executables to weaponized PDF files-are tailored to blend seamlessly into the Xinchuang environment, targeting both government and enterprise users.
One standout tactic involves malicious .desktop files, the Linux equivalent of Windows shortcuts. When unsuspecting users open a file like “Notice on Printing and Distributing the Minutes of the 2025 Meeting of the Energy Industry Shale Gas Standardization Technical Committee.pdf.desktop,” hidden commands execute in the background, launching persistent channels for command-and-control (C2) communications.
OceanLotus has also capitalized on the widespread use of Java in Chinese ICT infrastructure. Bait files such as “The Path Dispute of the Asia-Pacific Free Trade Area and China’s Plan.jar” install advanced downloaders after verifying the system environment, a move reflecting the group’s technical sophistication and adaptability.
In a bold technical leap, the hackers exploited CVE-2023-52076-a critical bug in the Atril Document Viewer, common in Linux MATE desktops. By distributing a malicious EPUB file, they managed to embed persistent, encrypted Python downloaders and autostart scripts, ensuring long-term access to compromised machines.
Supply Chain Intrusions: The Next Front
Beyond phishing, OceanLotus is now attacking the internal supply chains of Xinchuang-based networks. After gaining a foothold, the group conducted month-long reconnaissance missions, followed by brute-force attacks and the exploitation of yet-unknown vulnerabilities to push malicious software updates. This approach allows them to compromise entire networks from within, escalating their impact far beyond individual victims.
The group’s pivot to Linux and domestically curated Chinese platforms signals a significant evolution in their strategy-one that could have ripple effects for supply chain security and IT sovereignty across the region.



