APT32 — APT Profile
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.Also tracked as
SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH
Tools & malware
- apk.phantomlance Mobile Malware
- Arp Network Reconnaissance
- Cobalt Strike Adversary Simulation
- Denis Backdoor
- elf.caja Backdoor
- elf.rotajakiro Backdoor
- Goopy Backdoor
- ipconfig Network Reconnaissance
- js.cactustorch Loader
- js.unidentified_001 Backdoor
- Kerrdown Backdoor
- KOMPROGO Backdoor
- Mimikatz Credential Harvesting
- Net Network Reconnaissance
- netsh LOLBin
- OSX_OCEANLOTUS.D Backdoor
- osx.oceanlotus Backdoor
- PHOREAL Backdoor
- RotaJakiro Backdoor
- SOUNDBITE Backdoor
- win.cobalt_strike Adversary Simulation
- win.cuegoe Backdoor
- win.kerrdown Backdoor
- win.komprogo Backdoor
- win.metaljack Backdoor
- win.mimikatz Credential Harvesting
- win.phoreal Backdoor
- win.ratsnif Remote Access Trojan
- win.salgorea Backdoor
- win.soundbite Backdoor
- win.strikesuit_gift Backdoor
- win.unidentified_068 Backdoor
- WINDSHIELD Backdoor
Vendor research
- SentinelOne SentinelOne
- How Microsoft names threat actors Microsoft
- OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP Cybereason
- Fake or Fake: Keeping up with OceanLotus decoys ESET
- Vietnamese activists targeted by notorious hacking group Amnesty Intl
- OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society Volexity
- OceanLotus ships new backdoor using old tricks ESET
- Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations FireEye