NEW: Group Profiler — instant APT intel lookup. Try it →

APT32

G0050 Vietnam Espionage MITRE ATT&CK →

Also known as: SeaLotus · OceanLotus · APT-C-00 · Canvas Cyclone · BISMUTH

Overview

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

Naming & attribution

APT32 is tracked under 6 names across the industry. It uses 78 documented ATT&CK techniques — more than 95% of the 174 groups tracked here. Activity attributed since at least 2014.

Who calls this group what — MITRE lists each alias with the report that used it, but not which vendor coined it.
NameFirst reported by
SeaLotusDahan, A
OceanLotusCarr, N.
APT-C-00Foltýn, T
Canvas CycloneMicrosoft
BISMUTHMicrosoft
APT32Carr, N.

Distinctive techniques

Techniques this group uses that are rare across the other 173 tracked groups — these carry more signal than the near-universal ones.

  • T1216.001 PubPrn — used by 1 of 174 groups
  • T1564.004 NTFS File Attributes — used by 1 of 174 groups
  • T1027.011 Fileless Storage — used by 2 of 174 groups
  • T1137 Office Application Startup — used by 2 of 174 groups
  • T1222.002 Linux and Mac Permissions — used by 3 of 174 groups
  • T1550.003 Pass the Ticket — used by 3 of 174 groups
  • T1552.002 Credentials in Registry — used by 3 of 174 groups

Closest groups by technique overlap

Computed from shared ATT&CK techniques. Overlap is not attribution — distinct actors converge on the same tradecraft — but a high share is a useful pivot.

Malware families with current indicators

One family attributed to APT32, carrying 6 indicators currently tracked from abuse.ch ThreatFox, MalwareBazaar, URLhaus and SSLBL. MITRE documents what a group does; this is what its tooling is doing now.

  • RotaJakiro 6 indicators

Browse or copy the indicators by hash, domain, IP or URL, filtered by age from 1 day to 3 years.

Targets

Civil society · Dissidents · Government · Journalists · Private sector

Regions

Association of Southeast Asian Nations · China · Germany · Philippines · United States · Vietnam

Capabilities

  • Exploitation of public-facing / client applications — ATT&CK T1203
  • Custom malware/implant development — ATT&CK: 10 attributed custom malware families

TTPs — 78 techniques across 14 tactics

Reconnaissance

Resource Development

Initial Access

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Lateral Movement

Collection

Command and Control

Tools & malware (15)

Mimikatz · ipconfig · Kerrdown · Cobalt Strike · SOUNDBITE · OSX_OCEANLOTUS.D · KOMPROGO · netsh · RotaJakiro · PHOREAL · Arp · WINDSHIELD · Denis · Net · Goopy

Reporting (3)