OceanLotus: From external espionage to domestic targeting

2026-06-12T08:51:40Z45d6b011936db396e3ea49edbfe9552c152fdf52405a57fb2fe7a40e0cc32ef6
AI threatsAPTAndroid malwareBTMOBCallPhantomEDR evasionFrostyNeighborGopherWhisperNFC payment fraudNGateOceanLotusRATSMB securityScarCruftSednitWebwormcloud workload securityphishingprivacyransomwarescamssupply-chain attacktrojanized appzero-day

What happened

A recent ESET WeLiveSecurity content feed highlights a surge in APT and mobile-focused activity plus broad guidance on cyber-resilience. Key research calls out operational shifts and new tooling from multiple APTs (OceanLotus pivoting to domestic targeting; new and active groups like GopherWhisper, Webworm, FrostyNeighbor, Sednit, ScarCruft), several mobile threats and supply‑chain abuses (BTMOB RAT, trojanized NFC payment app with a new NGate variant, CallPhantom fraudulent Play Store apps), and techniques to evade EDR (EDR killers). The feed also covers high-risk topics including supply‑side

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
eset_welivesecurity
Record identifier
45d6b011936db396e3ea49edbfe9552c152fdf52405a57fb2fe7a40e0cc32ef6
Enrichment time
2026-06-12T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.