APT32

MITRE ATT&CK: G0050 View on attack.mitre.org

Aliases: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, OceanLotus Group, Ocean Lotus, Cobalt Kitty, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, APT32, OCEAN BUFFALO

First seen
2014-01-01 00:00:00
Origin
VN
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
Espionage
Related IoCs
12 (4 malicious)
Last IoC activity
2026-08-24 08:14:53
Profile updated
2026-07-07 12:32:36

Targeted industries: government-and-public-sector media-and-entertainment professional-services technology-and-telecommunications

Targeted regions: country_code:vn country_code:ph country_code:la country_code:kh

Context

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to APT32 (G0050). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname tefanortin.com 2026-07-11 2
file sample 09b9f43c8c70c9d1e2aded67a6c4b4e743e6e5886a25995abd40ad663fa07238 2026-04-16 1
hostname ucairtz.com 2026-03-02 2
file sample e652d9d69aa49fd91e107888c1790067a757750c99223cddceeee2676cfbe6b1 2024-07-11 2

Detection coverage

  • 157 YARA rules
  • 843 Sigma rules

Malware & tools used

  • Pass the Hash (attack-pattern)
  • Masquerading (attack-pattern)
  • JavaScript (attack-pattern)
  • Windows Management Instrumentation (attack-pattern)
  • Software Deployment Tools (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • NTFS File Attributes (attack-pattern)
  • Credentials in Registry (attack-pattern)
  • Process Injection (attack-pattern)
  • PubPrn (attack-pattern)
  • Spearphishing Attachment (attack-pattern)
  • Network Share Discovery (attack-pattern)
  • System Owner/User Discovery (attack-pattern)
  • Non-Standard Port (attack-pattern)
  • System Information Discovery (attack-pattern)
  • Domains (attack-pattern)
  • Query Registry (attack-pattern)
  • Command Obfuscation (attack-pattern)
  • Windows Command Shell (attack-pattern)
  • Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
  • DLL (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Spearphishing Link (attack-pattern)
  • Local Account (attack-pattern)
  • PowerShell (attack-pattern)

Reports & references

  • MITRE ATT&CK — G0050 (report)
  • Mandiant — Cyber Espionage Apt32 (report)
  • cybereason.com — Labs Operation Cobalt Kitty A Large Scale Apt In Asia Carried Out By The Oceanlotus Group (report)
  • scmagazineuk.com — 663565 (report)
  • brighttalk.com — 261205 (report)
  • github.com — Oceanlotus (report)
  • cfr.org — Ocean Lotus (report)
  • accenture.com — Blogs Pond Loach Delivers Badcake Malware (report)
  • secureworks.com — Tin Woodlawn (report)
  • volexity.com — Oceanlotus Extending Cyber Espionage Operations Through Fake Websites (report)
  • Trend Micro — New Macos Backdoor Connected To Oceanlotus Surfaces (report)
  • Microsoft — Threat Actor Leverages Coin Miner Techniques To Stay Under The Radar Heres How To Spot Them (report)
  • about.fb.com — Taking Action Against Hackers In Bangladesh And Vietnam (report)
  • raw.githubusercontent.com — Microsoftmapping (report)
  • Microsoft — Microsoft Threat Actor Naming (report)
  • amnestyusa.org — Click And Bait Vietnamese Human Rights Defenders Targeted With Spyware Attacks (report)
  • cybereason.com — Operation Cobalt Kitty Apt (report)
  • volexity.com — Oceanlotus Blossoms Mass Digital Surveillance And Exploitation Of Asean Nations The Media Human Rights And Civil Society (report)
  • ESET — Oceanlotus Ships New Backdoor (report)
  • ESET — Fake Or Fake Keeping Up With Oceanlotus Decoys (report)

External references