Operation Ratsnif OceanLotus

The threat group behind the campaign is using the Ratsnif remote access trojan family to carry out attacks that perform a range of malicious activity including packet sniffing, ARP poisoning, DNS poisoning, HTTP injection, and MAC spoofing. The group of trojans have been under active development since 2016.
Operation Ratsnif OceanLotus 2019-07-18