Executive Summary
OceanSalt is a Windows trojan leveraged in targeted campaigns against South Korea, the United States, and Canada. It shares code with SpyNote RAT and has been linked to APT1 activity. The malware facilitates remote access, credential theft, and stealthy data exfiltration through encrypted channels.
Enhanced Description
OceanSalt is a Windows‑targeted Trojan that was identified in attacks against victims in South Korea, the United States, and Canada. Investigations revealed that OceanSalt shares substantial code similarity with SpyNote RAT—an existing remote access trojan long associated with APT1—which suggests that it inherits many of SpyNote’s capabilities such as persistent malicious processes, credential harvesting, and remote control features. The malware is delivered via spear‑phishing emails containing malicious attachments or links; once executed, OceanSalt establishes a covert communications channel to a command‑and‑control (C2) server, enabling the adversary to issue arbitrary commands, exfiltrate files, and maintain long‑term persistence on compromised systems. Behaviorally, OceanSalt is believed to utilize encrypted HTTP/HTTPS tunnels for C2 traffic, reducing detection by network monitoring. It likely registers itself in the system registry for automatic startup, injects into legitimate processes to hide its presence, and can harvest user credentials from common applications such as web browsers and Office suite components. While the full feature set has not been exhaustively documented, similarities with SpyNote RAT indicate that OceanSalt provides capabilities for data staging, file transfer, remote shell access, and lateral movement within targeted networks. Because of its multi‑nation footprint and apparent association with sophisticated threat actors, security teams should treat OceanSalt as a high‑risk intrusion vector. Proper endpoint protection, vigilant network monitoring, and thorough threat hunting are recommended to mitigate its impact across an organization’s information systems.
Key Capabilities
ATT&CK Techniques
Recommended Actions
Suggested Tags
Confidence Assessment
The available information about OceanSalt is limited and largely based on code similarity analysis with SpyNote RAT. No official malware samples or comprehensive behavioral reports are publicly disclosed in this dataset, creating gaps in understanding its full capabilities, deployment vectors, and impact metrics. Consequently, while the inference of core functionalities aligns with known RAT patterns, precise confidence levels for each capability remain moderate.
OceanSalt is a Trojan that was used in a campaign targeting victims in South Korea, United States, and Canada. OceanSalt shares code similarity with SpyNote RAT, which has been linked to APT1.(Citation: McAfee Oceansalt Oct 2018)