APT32 — APT Profile
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.Description reproduced from MITRE ATT&CK. © The MITRE Corporation, reproduced and distributed with permission.
Also tracked as
SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, OceanLotus Group, Cobalt Kitty, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, G0050
IntelFusions coverage (1)
- APT32's Multi-Stage macOS Trojan Innovates on Crimeware Scripting Techniques 2026-02-16 · Nation-State
Tools & malware
- apk.phantomlance Mobile Malware
- Arp Network Reconnaissance
- Cobalt Strike Adversary Simulation
- Denis Backdoor
- elf.caja Backdoor
- elf.rotajakiro Backdoor
- Goopy Backdoor
- ipconfig Network Reconnaissance
- js.cactustorch Loader
- js.unidentified_001 Backdoor
- Kerrdown Backdoor
- KOMPROGO Backdoor
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netsh LOLBin
- OSX_OCEANLOTUS.D Backdoor
- osx.oceanlotus Backdoor
- PHOREAL Backdoor
- RotaJakiro Backdoor
- SOUNDBITE Backdoor
- win.cobalt_strike Adversary Simulation
- win.cuegoe Backdoor
- win.kerrdown Backdoor
- win.komprogo Backdoor
- win.metaljack Backdoor
- win.mimikatz Credential Harvesting
- win.phoreal Backdoor
- win.ratsnif Remote Access Trojan
- win.salgorea Backdoor
- win.soundbite Backdoor
- win.strikesuit_gift Backdoor
- win.unidentified_068 Backdoor
- WINDSHIELD Backdoor
Vendor research
- Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations Carr, N.
- SentinelOne SentinelOne
- How Microsoft names threat actors Microsoft
- OceanLotus ships new backdoor using old tricks ESET
- OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society Volexity
- Vietnamese activists targeted by notorious hacking group Amnesty Intl
- Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations FireEye
- OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP Cybereason
- Fake or Fake: Keeping up with OceanLotus decoys ESET