Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Also known as: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, Ocean Lotus, SectorF01, Vietnam, OceanLotus Group, Cobalt Kitty, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, G0050

Description

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)

TTP Summary

Cobalt Kitty DLL Side-Loading: WinwordUpdates.exe → wwlib.dll (Microsoft) DLL Side-Loading: searchindexer.exe, searchprotoclhost.exe → msfte.dll DLL Side-Loading: googleupdate.exe → goopdate.dll (Google) DLL Side-Loading: avpia.exe → product_info.dll (Kaspersky)

Goals & Targeting

Targeted Sectors

Government
Media
Research

Targeted Countries / Regions

CN

AI Analysis

· 1 week ago

Executive Summary

APT32, also known as OceanLotus or SeaLotus, is a suspected Vietnamese-based threat group primarily involved in espionage activities targeting government, media, and research sectors across Southeast Asia, including China. Known for using sophisticated techniques like DLL side-loading with Cobalt Strike and leveraging process injection, APT32 poses a significant risk to sensitive data and organizational stability.

Goals & Targeting

APT32's strategic objectives focus on intelligence gathering to support political and military objectives, particularly within Southeast Asia. They target sectors that hold sensitive information, such as government ministries, media organizations, and research institutions, where data breaches can have significant geopolitical implications. Their geographic focus likely reflects efforts to influence regional dynamics and maintain control over domestic narratives through targeted attacks.

Enhanced Description

APT32 is a high-sophistication cyber threat group suspected to originate from Vietnam, active since at least 2014. They have extensively targeted government agencies, media outlets, and research institutions in Southeast Asia, including China, the Philippines, Laos, and Cambodia. Their primary motive appears to be espionage, aiming to gather sensitive information for political or strategic advantage. APT32 is known for their use of Cobalt Strike, a powerful toolset enabling process injection and credential dumping, as well as DLL side-loading techniques that exploit legitimate processes like Google Updater, Kaspersky antivirus, and Microsoft Office tools. Their TTPs include web compromises, spearphishing campaigns, and lateral movement within networks using Pass the Hash and other methods. Despite their extensive operations across Southeast Asia, there is limited clarity on whether APT32 operates as a state-sponsored entity or an independent group.

Key Capabilities

  • DLL side-loading exploitation
  • Cobalt Strike for process injection and credential dumping
  • Spearphishing campaigns using malicious links and attachments
  • Lateral movement techniques like Pass the Hash
  • Web compromise attacks against third-party services

MITRE ATT&CK Tactics

Credential Access
Discovery
Lateral Movement
Defense Evasion
Collection

ATT&CK Techniques

T1053.005
T1056.001
T1216.001
T1003
T1059.007
T1036.004
T1036.005
T1583.001
T1204.002
T1059.003

Software / Tooling

Cobalt Strike
Goopy
RotaJakiro
KOMPROGO
Denis
PHOREAL

Campaigns & Victims

APT32's campaigns often involve initial access via spearphishing or compromised websites, followed by extensive lateral movement to gather data over extended periods. Their operations in SE Asia suggest a focus on destabilizing regional politics and gathering intelligence from key institutions. Notable past activities include attacks against diplomatic missions and media entities, highlighting their ability to maintain persistent access.

IOC Patterns

  • DLL files dropped under common names (e.g., wwlib.dll)
  • Scheduled tasks linked to legitimate-sounding processes
  • Network traffic to known APT32 domains like [specific domain]
  • Presence of Cobalt Strike beacons in network traffic
  • Spearphishing emails with .doc attachments

Recommended Actions

  • Implement strong DMARC, SPF, DKIM policies to mitigate phishing.
  • Monitor for legitimate processes executing unexpected commands.
  • Segment networks and restrict lateral movement privileges.
  • Conduct regular security audits focusing on third-party vendor access.

Suggested Tags

APT
espionage
Southeast Asia

Confidence Assessment

High confidence in APT32's involvement in espionage activities based on multiple reports, but some uncertainty remains about their exact origin and whether they are state-sponsored. Additional clarity needed on their global operations beyond Southeast Asia.

ATT&CK Techniques

Command & Control
5 techniques
Discovery
10 techniques
Execution
12 techniques
Initial Access
3 techniques
Persistence
4 techniques
Resource Development
6 techniques
Stealth
20 techniques

Software / Tooling

Campaigns / Victims

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

  1. Amnesty Intl. Ocean Lotus February 2021 — Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021.
  2. FireEye APT32 May 2017 — Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.
  3. Cybereason Oceanlotus May 2017 — Dahan, A. (2017, May 24). OPERATION COBALT KITTY: A LARGE-SCALE APT IN ASIA CARRIED OUT BY THE OCEANLOTUS GROUP. Retrieved November 5, 2018.
  4. ESET OceanLotus Mar 2019 — Dumont, R. (2019, March 20). Fake or Fake: Keeping up with OceanLotus decoys. Retrieved April 1, 2019.
  5. ESET OceanLotus — Foltýn, T. (2018, March 13). OceanLotus ships new backdoor using old tricks. Retrieved May 22, 2018.
  6. Volexity OceanLotus Nov 2017 — Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017.
  7. Microsoft Threat Actor Naming July 2023 — Microsoft . (2023, July 12). How Microsoft names threat actors. Retrieved November 17, 2023.

Intel Summary

79

Techniques

14

Tools

1

Campaigns

0

IOCs

0

Observed Data

15

Tactics

Tags

APT
Government Targeting
espionage
Southeast Asia

Details

MITRE ID
G0050
Type
Unknown
Resource Level
Unknown
Primary Motivation
Espionage
Country of Origin
V
Confidence
90%
Added
May 2, 2026
STIX ID
intrusion-set--247cb30b-955f-42eb-97a5-a89fef69341e
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.