Threat intelligence
- Suspected origin
- Vietnam
- First seen
- 2013-01-01 00:00:00
- Motivation
- Information theft and espionage
- Targeted sectors
- Defense, Financial, Government, High-Tech, Hospitality, Manufacturing, Media, Retail, Telecommunications
- TLP
- WHITE
(FireEye) Since at least 2014, FireEye has observed APT32 targeting foreign corporations with a vested interest in Vietnam’s manufacturing, consumer products, and hospitality sectors. Furthermore, there are indications that APT32 actors are targeting peripheral network security and technology infrastructure corporations.
In addition to focused targeting of the private sector with ties to Vietnam, APT32 has also targeted foreign governments, as well as Vietnamese dissidents and journalists since at least 2013.
Also known as
APT 32APT-C-00APT-LY-100APT32ATK 17BISMUTHCanvas CycloneG0050Lotus BaneOcean BuffaloOceanLotusPond LoachSeaLotusSectorF01Tin Woodlawn
Vulnerabilities exploited
Tooling and malware
Cobalt StrikeDenisGoopyKerrdownKOMPROGOOSX_OCEANLOTUS.DPHOREALRotaJakiroSOUNDBITEWINDSHIELDArpipconfigMimikatzNetnetsh
MITRE ATT&CK techniques
T1560 Archive Collected DataT1102 Web ServiceT1105 Ingress Tool TransferT1571 Non-Standard PortT1003 OS Credential DumpingT1112 Modify RegistryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1033 System Owner/User DiscoveryT1046 Network Service DiscoveryT1049 System Network Connections DiscoveryT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1135 Network Share DiscoveryT1047 Windows Management InstrumentationT1059 Command and Scripting InterpreterT1072 Software Deployment ToolsT1203 Exploitation for Client ExecutionT1041 Exfiltration Over C2 ChannelT1189 Drive-by CompromiseT1570 Lateral Tool TransferT1137 Office Application StartupT1068 Exploitation for Privilege EscalationT1589 Gather Victim Identity InformationT1036 MasqueradingT1055 Process Injection
Coverage 2
threat-intel
OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction…

supply-chain
Securelist researchers identified a PyPI supply chain attack orchestrated by OceanLotus, utilizing seemingly legitimate Python packages (uuid32-utils, colorinal, and termncolor) to deliver the previously unknown malware…
