OceanLotus Targets Xinchuang Ecosystem with Sophisticated Supply Chain Attacks
Cybersecurity The advanced persistent threat group, OceanLotus (APT32), has initiated a cyberespionage campaign targeting China's Xinchuang initiative, which aims to replace foreign technology with secure, domestic IT ecosystems. Targeting Linux Systems OceanLotus has shifted from Windows-centric attacks to targeting Linux-based…

Cybersecurity
The advanced persistent threat group, OceanLotus (APT32), has initiated a cyberespionage campaign targeting China's Xinchuang initiative, which aims to replace foreign technology with secure, domestic IT ecosystems.
Targeting Linux Systems
OceanLotus has shifted from Windows-centric attacks to targeting Linux-based operating systems and internal supply chains. Security researchers have identified spear-phishing attacks throughout 2025 that adapt Windows attack methods for Linux environments within Xinchuang infrastructure.
The group uses Desktop Entry files (.desktop) as bait, disguised as legitimate documents. Upon execution, these files run a base64-encoded bash command, creating a scheduled task for persistent command-and-control (C2) communication. Additionally, attackers exploit pre-installed Java and Python environments on government ICT terminals.
OceanLotus has shifted from Windows-centric attacks to targeting Linux-based operating systems and internal supply chains.
Exploiting Document Viewer Vulnerabilities
In mid-2025, OceanLotus exploited CVE-2023-52076, a path traversal and arbitrary file write vulnerability in the Atril Document Viewer. By distributing malicious EPUB files, the attackers triggered the vulnerability to write a persistence file into the system's autostart directory and an encrypted payload into the .config folder, bypassing standard user defenses.
Internal Supply Chain Compromise
OceanLotus has shifted focus to internal network supply chain attacks, compromising domestic software used for terminal management. After initial access through phishing, the attackers attempted to brute-force internal security servers and likely deployed a zero-day exploit when brute-force attempts failed. Once in control of the management server, they distributed malicious update scripts to downstream endpoints, affecting both Linux-based Xinchuang terminals and legacy Windows systems.
This campaign underscores the evolving capabilities of OceanLotus, highlighting that even indigenized operating systems are vulnerable to advanced persistent threats when attackers exploit specific tools and supply chains designed to secure them.



