APT32
MITRE ATT&CK: G0050 View on attack.mitre.org
Aliases: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, OceanLotus Group, Ocean Lotus, Cobalt Kitty, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, APT32, OCEAN BUFFALO
- First seen
- 2014-01-01 00:00:00
- Origin
- VN
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- Espionage
- Related IoCs
- 12 (4 malicious)
- Last IoC activity
- 2026-08-24 08:14:53
- Profile updated
- 2026-07-07 12:32:36
Targeted industries: government-and-public-sector media-and-entertainment professional-services technology-and-telecommunications
Targeted regions: country_code:vn country_code:ph country_code:la country_code:kh
Context
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
Recent IoC activity
4 malicious indicators in Maltiverse are attributed to APT32 (G0050). The 4 most recently updated:
| Type | Indicator | Updated | Sources |
|---|---|---|---|
| hostname | tefanortin.com | 2026-07-11 | 2 |
| file sample | 09b9f43c8c70c9d1e2aded67a6c4b4e743e6e5886a25995abd40ad663fa07238 | 2026-04-16 | 1 |
| hostname | ucairtz.com | 2026-03-02 | 2 |
| file sample | e652d9d69aa49fd91e107888c1790067a757750c99223cddceeee2676cfbe6b1 | 2024-07-11 | 2 |
Detection coverage
- 157 YARA rules
- 843 Sigma rules
Malware & tools used
- Pass the Hash (attack-pattern)
- Masquerading (attack-pattern)
- JavaScript (attack-pattern)
- Windows Management Instrumentation (attack-pattern)
- Software Deployment Tools (attack-pattern)
- Lateral Tool Transfer (attack-pattern)
- NTFS File Attributes (attack-pattern)
- Credentials in Registry (attack-pattern)
- Process Injection (attack-pattern)
- PubPrn (attack-pattern)
- Spearphishing Attachment (attack-pattern)
- Network Share Discovery (attack-pattern)
- System Owner/User Discovery (attack-pattern)
- Non-Standard Port (attack-pattern)
- System Information Discovery (attack-pattern)
- Domains (attack-pattern)
- Query Registry (attack-pattern)
- Command Obfuscation (attack-pattern)
- Windows Command Shell (attack-pattern)
- Exfiltration Over Unencrypted Non-C2 Protocol (attack-pattern)
- DLL (attack-pattern)
- Spearphishing Link (attack-pattern)
- Spearphishing Link (attack-pattern)
- Local Account (attack-pattern)
- PowerShell (attack-pattern)
Reports & references
- MITRE ATT&CK — G0050 (report)
- Mandiant — Cyber Espionage Apt32 (report)
- cybereason.com — Labs Operation Cobalt Kitty A Large Scale Apt In Asia Carried Out By The Oceanlotus Group (report)
- scmagazineuk.com — 663565 (report)
- brighttalk.com — 261205 (report)
- github.com — Oceanlotus (report)
- cfr.org — Ocean Lotus (report)
- accenture.com — Blogs Pond Loach Delivers Badcake Malware (report)
- secureworks.com — Tin Woodlawn (report)
- volexity.com — Oceanlotus Extending Cyber Espionage Operations Through Fake Websites (report)
- Trend Micro — New Macos Backdoor Connected To Oceanlotus Surfaces (report)
- Microsoft — Threat Actor Leverages Coin Miner Techniques To Stay Under The Radar Heres How To Spot Them (report)
- about.fb.com — Taking Action Against Hackers In Bangladesh And Vietnam (report)
- raw.githubusercontent.com — Microsoftmapping (report)
- Microsoft — Microsoft Threat Actor Naming (report)
- amnestyusa.org — Click And Bait Vietnamese Human Rights Defenders Targeted With Spyware Attacks (report)
- cybereason.com — Operation Cobalt Kitty Apt (report)
- volexity.com — Oceanlotus Blossoms Mass Digital Surveillance And Exploitation Of Asean Nations The Media Human Rights And Civil Society (report)
- ESET — Oceanlotus Ships New Backdoor (report)
- ESET — Fake Or Fake Keeping Up With Oceanlotus Decoys (report)
External references
- mitre-attack — G0050
- SeaLotus
- APT-C-00
- APT32
- OceanLotus
- Canvas Cyclone
- BISMUTH
- Amnesty Intl. Ocean Lotus February 2021
- FireEye APT32 May 2017
- Cybereason Oceanlotus May 2017
- ESET OceanLotus Mar 2019
- ESET OceanLotus
- Volexity OceanLotus Nov 2017
- Microsoft Threat Actor Naming July 2023
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy
- misp-galaxy