{"id":50782,"date":"2016-02-19T09:33:51","date_gmt":"2016-02-19T17:33:51","guid":{"rendered":"https:\/\/www.intego.com\/mac-security-blog\/?p=50782"},"modified":"2026-07-01T13:57:11","modified_gmt":"2026-07-01T20:57:11","slug":"oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update","status":"publish","type":"post","link":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/","title":{"rendered":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-50788\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-600x300.jpeg\" alt=\"OceanLotus fake Flash update\" width=\"600\" height=\"300\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-600x300.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-600x300-150x75.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-600x300-300x150.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p>Intego VirusBarrier users are protected against the OS X version of OceanLotus, a sophisticated Trojan horse that has been used to spy against businesses and government agencies.<\/p>\n<p>In May last year, Chinese security firm Qihoo360 published a <a title=\"Link to Qihoo research\" href=\"http:\/\/drops.wooyun.org\/papers\/6335\" target=\"_blank\" rel=\"nofollow noopener\">technical paper<\/a> examining a malware campaign that was said to be targeting critical areas of Chinese infrastructure \u2014 including government offices, research institutes, maritime agencies, construction and shipping enterprises.<\/p>\n<p>Sadly, Qihoo360&#8217;s paper is in Chinese (a language I don&#8217;t read!) and Google&#8217;s online translation is not perfect, but it is clear that the security firm had also seen a version of OceanLotus made specifically for the OS X platform.<\/p>\n<p>A recent <a title=\"Link to AlienVault report\" href=\"https:\/\/www.alienvault.com\/open-threat-exchange\/blog\/oceanlotus-for-os-x-an-application-bundle-pretending-to-be-an-adobe-flash-update\" target=\"_blank\" rel=\"nofollow noopener\">report<\/a> by AlienVault has brought this OS X version of OceanLotus back into the spotlight.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-50791\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/flashupdate-170.jpeg\" alt=\"Fake Flash Update\" width=\"170\" height=\"291\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/flashupdate-170.jpeg 170w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/flashupdate-170-88x150.jpeg 88w\" sizes=\"auto, (max-width: 170px) 100vw, 170px\" \/>There&#8217;s nothing particularly novel about the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/topic\/social-engineering\/\">social engineering<\/a> that OceanLotus uses to dupe users into infection, <a href=\"https:\/\/www.intego.com\/mac-security-blog\/how-to-tell-if-adobe-flash-player-update-is-valid\/\" target=\"_blank\" rel=\"noopener\">posing as an update to Adobe Flash<\/a>.<\/p>\n<p>But then, an attack&#8217;s social engineering doesn&#8217;t need to be sophisticated if it is effective. Malicious hackers know that their targets are used to being prompted to install updates to widely-used applications \u2014 such as Adobe Flash \u2014 and many will not be surprised to see a pop-up appear on their screen and will click to run code without thinking carefully about the potential dangers.<\/p>\n<p>And, you may be asking, how did the criminals get the fake version of Flash to users in the first place in order to hit them with the OceanLotus malware? It appears that OceanLotus has been\u00a0spread via two different methods.<\/p>\n<p>Firstly, the malware was\u00a0distributed via watering hole attacks. This is where a particular legitimate website is compromised by online criminals, who inject malicious code into its pages. Innocent visitors to the poisoned webpages have their computers infected via a drive-by download attack, or are socially engineered into installing software that then compromises their systems.<\/p>\n<p>Examples of possible watering hole sites include websites that might cover news about a particular topic, or forums that deal with a particular industry. Online criminals target particular sites, knowing that their targets are likely to regularly visit it. Examples would include the <a href=\"https:\/\/www.intego.com\/mac-security-blog\/os-x-malware-tibet-variant-found\/\" target=\"_blank\" rel=\"noopener\">OSX\/Tibet malware<\/a> that was distributed in the form of a <a href=\"https:\/\/www.grahamcluley.com\/2013\/09\/mac-malware\/\" target=\"_blank\" rel=\"noopener\">poisoned Java applet<\/a> on compromised websites, or <a href=\"https:\/\/www.intego.com\/mac-security-blog\/pint-sized-backdoor-for-os-x-discovered\/\" target=\"_blank\" rel=\"noopener\">OSX\/Pintsized<\/a> that successfully <a title=\"Link to Security Ledger article\" href=\"https:\/\/securityledger.com\/2013\/03\/many-watering-holes-targets-in-hacks-that-netted-facebook-twitter-and-apple\/\" target=\"_blank\" rel=\"nofollow noopener\">infected computer systems at Facebook, Twitter, Apple, and Microsoft<\/a>, amongst others.<\/p>\n<p>The other way that OceanLotus has been\u00a0distributed is\u00a0through spear-phishing attacks, where emails carrying malicious attachments or links are targeted at workers at specific organisations with the intention of tricking them into infection.<\/p>\n<p>Files used by the malware include:<\/p>\n<ul>\n<li>FlashUpdate.app\/Contents\/MacOS\/EmptyApplication<\/li>\n<li>FlashUpdate.app\/Contents\/Resources\/en.lproj\/.DS_Stores<\/li>\n<li>FlashUpdate.app\/Contents\/Resources\/en.lproj\/.en_icon<\/li>\n<\/ul>\n<p>The malware&#8217;s loader is encoded and it decodes itself to be able to decode other files, which are used to deploy the threat locally. This makes analysis (and the creation of protection routines) harder. When the Trojan is installed, a persistent daemon runs and performs several tasks from a command &amp; control (C&amp;C) server. During Intego&#8217;s laboratory tests, the C&amp;C servers appear to be currently offline.<\/p>\n<p>In the below image you can see <a href=\"https:\/\/www.intego.com\/antivirus-internet-security-x8#netbarrier-x8\" target=\"_blank\" rel=\"noopener\">Intego NetBarrier<\/a> alerting on an attempt by the malware to receive commands from the command &amp; control servers, in order to download additional payload code. If you see such a message you should obviously block the connection.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-50785\" src=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/netbarrier.jpeg\" alt=\"Intego NetBarrier\" width=\"600\" height=\"327\" srcset=\"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/netbarrier.jpeg 600w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/netbarrier-150x82.jpeg 150w, https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/netbarrier-300x164.jpeg 300w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/p>\n<p><a href=\"https:\/\/www.intego.com\/products\/intego-one-mac\" target=\"_blank\" rel=\"noopener\">Intego VirusBarrier<\/a> with up-to-date virus definitions will detect and eradicate the <strong>OSX\/OceanLotus<\/strong>\u00a0malware.<\/p>\n<p>Users are reminded that the only safe place to download security updates for Adobe Flash is directly from the Adobe website itself.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?<\/p>\n","protected":false},"author":34,"featured_media":50794,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[190,5],"tags":[1261,86,2800,168,2803,3172],"class_list":["post-50782","post","type-post","status-publish","format-standard","has-post-thumbnail","category-malware","category-security-news","tag-china","tag-mac-malware","tag-oceanlotus","tag-os-x","tag-osxoceanlotus","tag-social-engineering"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Graham Cluley\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"The Mac Security Blog - Keep Macs safe from the dangers of the Internet\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\" \/>\n\t\t<meta property=\"og:description\" content=\"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2016-02-19T17:33:51+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-07-01T20:57:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/integogroup\/\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@IntegoSecurity\" \/>\n\t\t<meta name=\"twitter:title\" content=\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@IntegoSecurity\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#blogposting\",\"name\":\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\",\"headline\":\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\",\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2016\\\/02\\\/ocean-lotus-400x260.jpeg\",\"width\":400,\"height\":260,\"caption\":\"OceanLotus Malware\"},\"datePublished\":\"2016-02-19T09:33:51-08:00\",\"dateModified\":\"2026-07-01T13:57:11-07:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#webpage\"},\"articleSection\":\"Malware, Security News, China, Malware, OceanLotus, OS X, OSX\\\/OceanLotus, Social Engineering, Graham Cluley\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"position\":2,\"name\":\"Security News\",\"item\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#listItem\",\"name\":\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#listItem\",\"position\":3,\"name\":\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/category\\\/security-news\\\/#listItem\",\"name\":\"Security News\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2026\\\/08\\\/logo2.png\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#organizationLogo\",\"width\":122,\"height\":46},\"image\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/integogroup\\\/\",\"https:\\\/\\\/x.com\\\/IntegoSecurity\",\"https:\\\/\\\/www.instagram.com\\\/intego_security\\\/\",\"https:\\\/\\\/www.youtube.com\\\/user\\\/IntegoVideo\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/intego\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/\",\"name\":\"Graham Cluley\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2237317b8942db4407872d4d6f8d61b4aa8f152370c257894dff14ed15a0c7da?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"Graham Cluley\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#webpage\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/\",\"name\":\"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update\",\"description\":\"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/author\\\/graham-cluley\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/wp-content\\\/uploads\\\/2016\\\/02\\\/ocean-lotus-400x260.jpeg\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#mainImage\",\"width\":400,\"height\":260,\"caption\":\"OceanLotus Malware\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\\\/#mainImage\"},\"datePublished\":\"2016-02-19T09:33:51-08:00\",\"dateModified\":\"2026-07-01T13:57:11-07:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#website\",\"url\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/\",\"name\":\"The Mac Security Blog\",\"description\":\"Keep Macs safe from the dangers of the Internet\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intego.com\\\/mac-security-blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>OceanLotus OS X Malware Disguises Itself as Adobe Flash Update<\/title>\n\n","aioseo_head_json":{"title":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","description":"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?","canonical_url":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#blogposting","name":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","headline":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-400x260.jpeg","width":400,"height":260,"caption":"OceanLotus Malware"},"datePublished":"2016-02-19T09:33:51-08:00","dateModified":"2026-07-01T13:57:11-07:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#webpage"},"isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#webpage"},"articleSection":"Malware, Security News, China, Malware, OceanLotus, OS X, OSX\/OceanLotus, Social Engineering, Graham Cluley"},{"@type":"BreadcrumbList","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","position":1,"name":"Home","item":"https:\/\/www.intego.com\/mac-security-blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","position":2,"name":"Security News","item":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#listItem","name":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#listItem","position":3,"name":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","previousItem":{"@type":"ListItem","@id":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/#listItem","name":"Security News"}}]},{"@type":"Organization","@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","url":"https:\/\/www.intego.com\/mac-security-blog\/","logo":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2026\/08\/logo2.png","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#organizationLogo","width":122,"height":46},"image":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/integogroup\/","https:\/\/x.com\/IntegoSecurity","https:\/\/www.instagram.com\/intego_security\/","https:\/\/www.youtube.com\/user\/IntegoVideo","https:\/\/www.linkedin.com\/company\/intego"]},{"@type":"Person","@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author","url":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/","name":"Graham Cluley","image":{"@type":"ImageObject","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/2237317b8942db4407872d4d6f8d61b4aa8f152370c257894dff14ed15a0c7da?s=96&d=mm&r=g","width":96,"height":96,"caption":"Graham Cluley"}},{"@type":"WebPage","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#webpage","url":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/","name":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","description":"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#breadcrumblist"},"author":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"creator":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/author\/graham-cluley\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.intego.com\/mac-security-blog\/wp-content\/uploads\/2016\/02\/ocean-lotus-400x260.jpeg","@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#mainImage","width":400,"height":260,"caption":"OceanLotus Malware"},"primaryImageOfPage":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/#mainImage"},"datePublished":"2016-02-19T09:33:51-08:00","dateModified":"2026-07-01T13:57:11-07:00"},{"@type":"WebSite","@id":"https:\/\/www.intego.com\/mac-security-blog\/#website","url":"https:\/\/www.intego.com\/mac-security-blog\/","name":"The Mac Security Blog","description":"Keep Macs safe from the dangers of the Internet","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.intego.com\/mac-security-blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"The Mac Security Blog - Keep Macs safe from the dangers of the Internet","og:type":"article","og:title":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","og:description":"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?","og:url":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/","article:published_time":"2016-02-19T17:33:51+00:00","article:modified_time":"2026-07-01T20:57:11+00:00","article:publisher":"https:\/\/www.facebook.com\/integogroup\/","twitter:card":"summary_large_image","twitter:site":"@IntegoSecurity","twitter:title":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","twitter:description":"Is your Mac protected against the OS X version of OceanLotus, a sophisticated trojan horse that has been used to spy against businesses and government agencies?","twitter:creator":"@IntegoSecurity"},"aioseo_meta_data":{"post_id":"50782","title":null,"description":null,"keywords":null,"keyphrases":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":null,"twitter_description":null,"schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":"2026-09-03 14:13:09","created":"2026-09-03 14:13:09","updated":"2026-09-04 14:25:31","reviewed_by":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/\" title=\"Security News\">Security News<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\tOceanLotus OS X Malware Disguises Itself as Adobe Flash Update\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.intego.com\/mac-security-blog"},{"label":"Security News","link":"https:\/\/www.intego.com\/mac-security-blog\/category\/security-news\/"},{"label":"OceanLotus OS X Malware Disguises Itself as Adobe Flash Update","link":"https:\/\/www.intego.com\/mac-security-blog\/oceanlotus-os-x-malware-disguises-itself-as-adobe-flash-update\/"}],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/50782","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/users\/34"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/comments?post=50782"}],"version-history":[{"count":20,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/50782\/revisions"}],"predecessor-version":[{"id":105332,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/posts\/50782\/revisions\/105332"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media\/50794"}],"wp:attachment":[{"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/media?parent=50782"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/categories?post=50782"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intego.com\/mac-security-blog\/wp-json\/wp\/v2\/tags?post=50782"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}