OceanLotus: From external espionage to domestic targeting
2026-06-12T08:51:40Z•45d6b011936db396e3ea49edbfe9552c152fdf52405a57fb2fe7a40e0cc32ef6
AI threatsAPTAndroid malwareBTMOBCallPhantomEDR evasionFrostyNeighborGopherWhisperNFC payment fraudNGateOceanLotusRATSMB securityScarCruftSednitWebwormcloud workload securityphishingprivacyransomwarescamssupply-chain attacktrojanized appzero-day
What happened
A recent ESET WeLiveSecurity content feed highlights a surge in APT and mobile-focused activity plus broad guidance on cyber-resilience. Key research calls out operational shifts and new tooling from multiple APTs (OceanLotus pivoting to domestic targeting; new and active groups like GopherWhisper, Webworm, FrostyNeighbor, Sednit, ScarCruft), several mobile threats and supply‑chain abuses (BTMOB RAT, trojanized NFC payment app with a new NGate variant, CallPhantom fraudulent Play Store apps), and techniques to evade EDR (EDR killers). The feed also covers high-risk topics including supply‑side
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- 45d6b011936db396e3ea49edbfe9552c152fdf52405a57fb2fe7a40e0cc32ef6
- Enrichment time
- 2026-06-12T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.