FORENSIA

THREAT_ACTOR · G0050

APT32

Also known as: APT32, SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH

Profile

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

MITRE ATT&CK ↗

Techniques

78 ATT&CK techniques attributed to this actor.

T1003 OS Credential DumpingT1003.001 LSASS MemoryT1012 Query RegistryT1016 System Network Configuration DiscoveryT1018 Remote System DiscoveryT1021.002 SMB/Windows Admin SharesT1027.010 Command ObfuscationT1027.011 Fileless StorageT1027.013 Encrypted/Encoded FileT1027.016 Junk Code InsertionT1033 System Owner/User DiscoveryT1036 MasqueradingT1036.003 Rename Legitimate UtilitiesT1036.004 Masquerade Task or ServiceT1036.005 Match Legitimate Resource Name or LocationT1041 Exfiltration Over C2 ChannelT1046 Network Service DiscoveryT1047 Windows Management InstrumentationT1048.003 Exfiltration Over Unencrypted Non-C2 ProtocolT1049 System Network Connections DiscoveryT1053.005 Scheduled TaskT1055 Process InjectionT1056.001 KeyloggingT1059 Command and Scripting InterpreterT1059.001 PowerShellT1059.003 Windows Command ShellT1059.005 Visual BasicT1059.007 JavaScriptT1068 Exploitation for Privilege EscalationT1070.004 File DeletionT1070.006 TimestompT1071.001 Web ProtocolsT1071.003 Mail ProtocolsT1072 Software Deployment ToolsT1078.003 Local AccountsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1087.001 Local AccountT1102 Web ServiceT1105 Ingress Tool TransferT1112 Modify RegistryT1135 Network Share DiscoveryT1137 Office Application StartupT1189 Drive-by CompromiseT1203 Exploitation for Client ExecutionT1204.001 Malicious LinkT1204.002 Malicious FileT1216.001 PubPrnT1218.005 MshtaT1218.010 Regsvr32T1218.011 Rundll32T1222.002 Linux and Mac PermissionsT1505.003 Web ShellT1543.003 Windows ServiceT1547.001 Registry Run Keys / Startup FolderT1550.002 Pass the HashT1550.003 Pass the TicketT1552.002 Credentials in RegistryT1560 Archive Collected DataT1564.001 Hidden Files and DirectoriesT1564.003 Hidden WindowT1564.004 NTFS File AttributesT1566.001 Spearphishing AttachmentT1566.002 Spearphishing LinkT1569.002 Service ExecutionT1570 Lateral Tool TransferT1571 Non-Standard PortT1574.001 DLLT1583.001 DomainsT1583.006 Web ServicesT1585.001 Social Media AccountsT1588.002 ToolT1589 Gather Victim Identity InformationT1589.002 Email AddressesT1598.003 Spearphishing LinkT1608.001 Upload MalwareT1608.004 Drive-by TargetT1685.005 Clear Windows Event Logs

Software

15 malware/tools attributed to this actor.

MimikatzNetArpipconfignetshCobalt StrikeWINDSHIELDKOMPROGOSOUNDBITEPHOREALOSX_OCEANLOTUS.DDenisGoopyKerrdownRotaJakiro

Related corpus activity

10,454 indicators EXHIBIT techniques this actor uses. This is a shared-technique signal, not a first-party attribution to APT32.

IndicatorTypeFamilySevSrc
cve-2023-44976cveransomware852
cve-2026-1969cve851
cve-2025-68670cve852
cve-2026-3102cve853
cve-2025-34117cve851
cve-2021-29441cve851
cve-2026-22584cve852
cve-2025-11837cve852
cve-2025-34054cve854
cve-2014-2321cve851
cve-2020-22653cve852
cve-2025-2492cve852
cve-2017-18377cve851
cve-2021-25646cve851
cve-2025-66478cve852
cve-2025-0921cve852
cve-2021-27076cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2016-15047cve854
cve-2024-1781cve851
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-17456cve851
cve-2022-47945cve851
cve-2020-22658cve852
cve-2025-23304cve852
cve-2026-4368cveransomware851
cve-2013-7471cve851
cve-2026-0740cve851

Showing the top 30 by severity of 10,454.