Also known as: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, Ocean Lotus, SectorF01, Vietnam, OceanLotus Group, Cobalt Kitty, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, G0050
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)
Cobalt Kitty DLL Side-Loading: WinwordUpdates.exe → wwlib.dll (Microsoft) DLL Side-Loading: searchindexer.exe, searchprotoclhost.exe → msfte.dll DLL Side-Loading: googleupdate.exe → goopdate.dll (Google) DLL Side-Loading: avpia.exe → product_info.dll (Kaspersky)
Targeted Sectors
Targeted Countries / Regions
Executive Summary
APT32, also known as OceanLotus or SeaLotus, is a suspected Vietnamese-based threat group primarily involved in espionage activities targeting government, media, and research sectors across Southeast Asia, including China. Known for using sophisticated techniques like DLL side-loading with Cobalt Strike and leveraging process injection, APT32 poses a significant risk to sensitive data and organizational stability.
Goals & Targeting
APT32's strategic objectives focus on intelligence gathering to support political and military objectives, particularly within Southeast Asia. They target sectors that hold sensitive information, such as government ministries, media organizations, and research institutions, where data breaches can have significant geopolitical implications. Their geographic focus likely reflects efforts to influence regional dynamics and maintain control over domestic narratives through targeted attacks.
Enhanced Description
APT32 is a high-sophistication cyber threat group suspected to originate from Vietnam, active since at least 2014. They have extensively targeted government agencies, media outlets, and research institutions in Southeast Asia, including China, the Philippines, Laos, and Cambodia. Their primary motive appears to be espionage, aiming to gather sensitive information for political or strategic advantage. APT32 is known for their use of Cobalt Strike, a powerful toolset enabling process injection and credential dumping, as well as DLL side-loading techniques that exploit legitimate processes like Google Updater, Kaspersky antivirus, and Microsoft Office tools. Their TTPs include web compromises, spearphishing campaigns, and lateral movement within networks using Pass the Hash and other methods. Despite their extensive operations across Southeast Asia, there is limited clarity on whether APT32 operates as a state-sponsored entity or an independent group.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
APT32's campaigns often involve initial access via spearphishing or compromised websites, followed by extensive lateral movement to gather data over extended periods. Their operations in SE Asia suggest a focus on destabilizing regional politics and gathering intelligence from key institutions. Notable past activities include attacks against diplomatic missions and media entities, highlighting their ability to maintain persistent access.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in APT32's involvement in espionage activities based on multiple reports, but some uncertainty remains about their exact origin and whether they are state-sponsored. Additional clarity needed on their global operations beyond Southeast Asia.
Cobalt Kitty
No observed data linked yet.
No IOCs linked yet.
79
Techniques
14
Tools
1
Campaigns
0
IOCs
0
Observed Data
15
Tactics