news.mlab.sh
Threat intelligence
Threat actor

APT 32

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
Vietnam
First seen
2013-01-01 00:00:00
Motivation
Information theft and espionage
Targeted sectors
Defense, Financial, Government, High-Tech, Hospitality, Manufacturing, Media, Retail, Telecommunications
TLP
WHITE

(FireEye) Since at least 2014, FireEye has observed APT32 targeting foreign corporations with a vested interest in Vietnam’s manufacturing, consumer products, and hospitality sectors. Furthermore, there are indications that APT32 actors are targeting peripheral network security and technology infrastructure corporations. In addition to focused targeting of the private sector with ties to Vietnam, APT32 has also targeted foreign governments, as well as Vietnamese dissidents and journalists since at least 2013.

Also known as

APT 32APT-C-00APT-LY-100APT32ATK 17BISMUTHCanvas CycloneG0050Lotus BaneOcean BuffaloOceanLotusPond LoachSeaLotusSectorF01Tin Woodlawn

Vulnerabilities exploited

Tooling and malware

Cobalt StrikeDenisGoopyKerrdownKOMPROGOOSX_OCEANLOTUS.DPHOREALRotaJakiroSOUNDBITEWINDSHIELDArpipconfigMimikatzNetnetsh

MITRE ATT&CK techniques

T1560 Archive Collected DataT1102 Web ServiceT1105 Ingress Tool TransferT1571 Non-Standard PortT1003 OS Credential DumpingT1112 Modify RegistryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1135 Network Share DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1072 Software Deployment ToolsT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1189 Drive-by CompromiseT1570 Lateral Tool TransferT1137 Office Application StartupT1068 Exploitation for Privilege EscalationT1589 Gather Victim Identity InformationT1036 MasqueradingT1055 Process Injection

Coverage 2