OCEANMAP
- First seen
- 2021-04-15 00:00:00
- Malware type
- backdoor, rat
- Family
- Malware family
- Profile updated
- 2026-07-07 14:27:44
Targeted industries: government-and-public-sector defense-and-aerospace
Targeted regions: country_code:us country_code:uk country_code:fr
Context
OCEANMAP is a sophisticated remote access tool (RAT) used by state-sponsored actors to conduct espionage against government and defense sectors. It provides attackers with backdoor access to compromised systems, enabling data exfiltration and surveillance activities.
Detection coverage
- 1 YARA rules
Detection rules
- HARFANGLAB_Masepie_Campaign_Oceanmap (yara-rule)
Reports & references
- github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
- cert.ssi.gouv.fr — Certfr 2025 Cti 007 (report)
- CERT-UA — 6276894 (report)
- harfanglab.io — Compromised Routers Infrastructure Target Europe Caucasus (report)
- thehackernews.com — Apt28 Hacker Group Targeting Europe (report)
- malpedia.caad.fkie.fraunhofer.de — Win.Oceanmap (report)
- medium.com — Analyzing Apt28S Oceanmap Backdoor Exploring Its C2 Server Artifacts Db2C3Cb4556B (report)