Skip to content
VietnamState-SponsoredActiveMITRE G0050Malpedia ↗

APT32

Vietnamese collection against foreign firms operating in-country, regional neighbours, and dissidents abroad — with unusually elaborate web infrastructure.

Open MITRE Navigator layer ↗Download profile JSON
Active
2014–present
Motivation
Espionage, IP Theft
Aliases
10
Exploited CVEs
2
ATT&CK techniques
10
Cited sources
7

Overview

APT32, widely known as OceanLotus, conducts collection on behalf of Vietnamese state interests, with a target set that is commercially motivated as much as it is political.

Its most distinctive characteristic is who it targets domestically: foreign companies operating in Vietnam, particularly in manufacturing, consumer products, hospitality, and automotive. Reporting has documented the group targeting the Vietnamese operations of multinational corporations in ways consistent with support for domestic industrial policy — collection that benefits Vietnamese firms competing with them.

Politically, the group targets regional governments across Southeast Asia — Cambodia, Laos, and the Philippines feature heavily — alongside dissidents, bloggers, and human rights activists in the Vietnamese diaspora.

The group built an unusually sophisticated web-based infrastructure for a mid-tier state actor. Volexity documented a network of more than a hundred websites, many impersonating legitimate Vietnamese news outlets, running selective profiling and exploitation frameworks that fingerprinted visitors and delivered payloads only to those matching a target profile — leaving ordinary visitors entirely unaffected and the infrastructure hard to detect from the outside.

In 2020 the group also targeted Chinese government entities involved in the COVID-19 response, seeking pandemic intelligence in the early weeks of the outbreak.

Attribution

Down to the named unit where public evidence supports it.

VietnamVietnamese state interests (specific service not publicly designated)Moderate confidence

Assessed as aligned with Vietnamese state interests by FireEye/Mandiant, Volexity, and ESET, based on targeting consistent with Vietnamese political and economic priorities, Vietnamese-language artifacts, and operational timing. No government has issued a formal attribution and no individuals have been indicted, making this a lower-confidence assessment than for Russian, Chinese, or DPRK groups.

Attributing sources

Cross-vendor naming crosswalk

10 designators across 9 organisations.

MITRE ATT&CK

index ↗
  • APT32

Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.

Microsoft Threat Intelligence

index ↗
  • Canvas CycloneFormerly BISMUTH
  • BISMUTHRetired designator

Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.

CrowdStrike

index ↗
  • Ocean Buffalo

Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.

Mandiant / Google Threat Intelligence

index ↗
  • APT32

APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.

Secureworks CTU

index ↗
  • TIN WOODLAWN

Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.

Palo Alto Networks Unit 42

index ↗
  • Sea Lotus

Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.

ESET Research

index ↗
  • OceanLotus

Descriptive names, frequently derived from the group's flagship malware family.

Kaspersky GReAT

index ↗
  • OceanLotus

Descriptive names, often coined from a distinctive string or artifact in the toolset.

CISA / NSA / FBI

index ↗
  • APT32 / OceanLotus

U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.

Targeting

Target geography

VietnamCambodiaLaosPhilippinesChinaGermanyUnited StatesJapan

Tools & malware

Custom tooling is a strong clustering signal; shared and commodity tooling is not.

Custom / bespoke

KerrDownloader

Custom downloader delivered via malicious documents and installers, staging further payloads.

Ratsnifmalware

Network packet manipulation tool supporting ARP poisoning, DNS spoofing, and HTTP injection.

Denis / Salgoreabackdoor

Backdoor family using DNS tunnelling for C2, used against government targets.

macOS OSX.OceanLotusbackdoor

macOS implant reflecting a target population with meaningful Mac usage in media and NGO sectors.

Fake news websitesutility

Over 100 sites impersonating Vietnamese news outlets, profiling visitors and exploiting only those matching a target profile.

Shared, commodity & living-off-the-land

Cobalt Strikeframework

Heavily customised Beacon deployments with bespoke malleable C2 profiles.

Exploited vulnerabilities

Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.

CVEUsage by APT32
CVE-2017-11882KEVransomware7.81 Feb 2018Equation Editor overflow in lure documents delivering KerrDown against regional government targets.SRCUnit 42
CVE-2017-0199KEVransomware7.81 Jun 2017OLE2link RTF exploit used in phishing against corporate and government targets in Southeast Asia.SRCMandiant / FireEye

Kill chain

How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.

7 stages · 10 techniques
  1. 07

    Impact

    1 technique·derived

    Cryptomining deployed as a decoy to misdirect incident responders.

Scroll horizontally · characteristic chain across documented operations, not a single incident

MITRE ATT&CK techniques

Grouped in kill-chain order.

Open in Navigator ↗
10 techniques across 7 tactics · 4 with actor-specific notes

Resource Development

1

Initial Access

2

Defense Evasion

2

Impact

1

Campaign timeline

  1. Fake News Website Network

    Over 100 websites impersonating legitimate Vietnamese news outlets, running profiling frameworks that fingerprinted visitors and delivered payloads only to those matching a target profile — leaving ordinary readers unaffected and the infrastructure difficult to detect externally.

    Media & JournalismNGO & Civil SocietyGovernment

Known to work with

Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.

Primary-source reporting

Curated links to the reports that established what is known about this group.