NEW: Group Profiler — instant APT intel lookup. Try it →

← threatfilter.dev / all groups / APT32

APT32

G0050 Vietnam Espionage MITRE ATT&CK →

Also known as: SeaLotus · OceanLotus · APT-C-00 · Canvas Cyclone · BISMUTH

Overview

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

Targets

Civil society · Dissidents · Government · Journalists · Private sector

Regions

Association of Southeast Asian Nations · China · Germany · Philippines · United States · Vietnam

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 10 attributed custom malware families

TTPs — 78 techniques across 14 tactics

Reconnaissance

Resource Development

Initial Access

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (15)

Mimikatz · ipconfig · Kerrdown · Cobalt Strike · SOUNDBITE · OSX_OCEANLOTUS.D · KOMPROGO · netsh · RotaJakiro · PHOREAL · Arp · WINDSHIELD · Denis · Net · Goopy

Reporting (3)