OCEANMAP

First seen
2021-04-15 00:00:00
Malware type
backdoor, rat
Family
Malware family
Profile updated
2026-07-07 14:27:44

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:us country_code:uk country_code:fr

Context

OCEANMAP is a sophisticated remote access tool (RAT) used by state-sponsored actors to conduct espionage against government and defense sectors. It provides attackers with backdoor access to compromised systems, enabling data exfiltration and surveillance activities.

Detection coverage

  • 1 YARA rules

Detection rules

  • HARFANGLAB_Masepie_Campaign_Oceanmap (yara-rule)

Reports & references

  • github.com — Apt28%20The%20Long%20Hand%20Of%20Russian%20Interests (report)
  • cert.ssi.gouv.fr — Certfr 2025 Cti 007 (report)
  • CERT-UA — 6276894 (report)
  • harfanglab.io — Compromised Routers Infrastructure Target Europe Caucasus (report)
  • thehackernews.com — Apt28 Hacker Group Targeting Europe (report)
  • malpedia.caad.fkie.fraunhofer.de — Win.Oceanmap (report)
  • medium.com — Analyzing Apt28S Oceanmap Backdoor Exploring Its C2 Server Artifacts Db2C3Cb4556B (report)

External references