OceanLotus: From external espionage to domestic targeting
2026-06-13T08:51:37Z•f67dd8fe1cb8896127ca200eb88b68aa65a4478e384ff16249afc301f9dbb041
AI-generated-exploitAPTAndroid-RATBTMOBCallPhantomEDR-killersFrostyNeighborGopherWhisperNGateOceanLotusSMB-securityScarCruftSednitWebwormcloud-securitymobile-fraudphishingprivacyransomwarescamssmart-glassessupply-chainzero-day
What happened
Collection of ESET WeLiveSecurity briefings (Mar–Jun 2026) summarizing active APT and malware activity, notable supply‑chain and mobile threats, and broader defensive guidance. Key technical findings include OceanLotus shifting toward domestic targeting, discovery of GopherWhisper targeting Mongolian government entities, Webworm and FrostyNeighbor tooling/technique updates, a ScarCruft supply‑chain compromise of gaming platforms, a new NGate variant hidden in a trojanized NFC payment app (potentially AI‑assisted), EDR‑killer abuse of vulnerable drivers, and a stealthy Android RAT (BTMOB). The
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- eset_welivesecurity
- Record identifier
- f67dd8fe1cb8896127ca200eb88b68aa65a4478e384ff16249afc301f9dbb041
- Enrichment time
- 2026-06-13T08:51:37Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.