Resource Development
1 technique·derived
Profiling frameworks fingerprinting visitors before payload delivery.
Vietnamese collection against foreign firms operating in-country, regional neighbours, and dissidents abroad — with unusually elaborate web infrastructure.
APT32, widely known as OceanLotus, conducts collection on behalf of Vietnamese state interests, with a target set that is commercially motivated as much as it is political.
Its most distinctive characteristic is who it targets domestically: foreign companies operating in Vietnam, particularly in manufacturing, consumer products, hospitality, and automotive. Reporting has documented the group targeting the Vietnamese operations of multinational corporations in ways consistent with support for domestic industrial policy — collection that benefits Vietnamese firms competing with them.
Politically, the group targets regional governments across Southeast Asia — Cambodia, Laos, and the Philippines feature heavily — alongside dissidents, bloggers, and human rights activists in the Vietnamese diaspora.
The group built an unusually sophisticated web-based infrastructure for a mid-tier state actor. Volexity documented a network of more than a hundred websites, many impersonating legitimate Vietnamese news outlets, running selective profiling and exploitation frameworks that fingerprinted visitors and delivered payloads only to those matching a target profile — leaving ordinary visitors entirely unaffected and the infrastructure hard to detect from the outside.
In 2020 the group also targeted Chinese government entities involved in the COVID-19 response, seeking pandemic intelligence in the early weeks of the outbreak.
Down to the named unit where public evidence supports it.
Assessed as aligned with Vietnamese state interests by FireEye/Mandiant, Volexity, and ESET, based on targeting consistent with Vietnamese political and economic priorities, Vietnamese-language artifacts, and operational timing. No government has issued a formal attribution and no individuals have been indicted, making this a lower-confidence assessment than for Russian, Chinese, or DPRK groups.
Attributing sources
10 designators across 9 organisations.
Assigns a stable Gxxxx group ID and adopts the most widely used public name. Deliberately conservative — MITRE merges clusters only when public reporting supports it.
Weather-event family encodes the attributed origin; the adjective is arbitrary. Renamed from the older element taxonomy (STRONTIUM, NOBELIUM, HAFNIUM) in April 2023. 'Storm-####' is a temporary designator for a cluster still in development.
Animal denotes attributed nation-state or motive; the adjective distinguishes clusters. The original public adversary taxonomy, in use since 2012.
APTxx for state-nexus espionage, FINxx for financially motivated, UNCxxxx ('uncategorized') for clusters not yet graduated to a named group. Many UNC numbers are later merged into an APT/FIN designator.
Metal prefix encodes attributed origin, paired with an arbitrary uppercase codeword.
Constellation denotes attributed origin or motive, adopted in 2023 to replace ad-hoc naming.
Descriptive names, frequently derived from the group's flagship malware family.
Descriptive names, often coined from a distinctive string or artifact in the toolset.
U.S. government advisories generally reference groups by the most common industry name plus the attributed unit. Joint advisories are the authoritative source for unit-level attribution.
Target sectors
Target geography
Custom tooling is a strong clustering signal; shared and commodity tooling is not.
Custom / bespoke
Custom downloader delivered via malicious documents and installers, staging further payloads.
Network packet manipulation tool supporting ARP poisoning, DNS spoofing, and HTTP injection.
Backdoor family using DNS tunnelling for C2, used against government targets.
macOS implant reflecting a target population with meaningful Mac usage in media and NGO sectors.
Over 100 sites impersonating Vietnamese news outlets, profiling visitors and exploiting only those matching a target profile.
Shared, commodity & living-off-the-land
Heavily customised Beacon deployments with bespoke malleable C2 profiles.
Filtered on the date this actor was first reported exploiting the flaw — not the CVE's publication date.
| CVE | Product | Usage by APT32 | ||
|---|---|---|---|---|
| CVE-2017-11882KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Feb 2018 | Equation Editor overflow in lure documents delivering KerrDown against regional government targets.SRCUnit 42 ↗ |
| CVE-2017-0199KEVransomware | 7.8 | Microsoft OfficeMicrosoft | 1 Jun 2017 | OLE2link RTF exploit used in phishing against corporate and government targets in Southeast Asia.SRCMandiant / FireEye ↗ |
Actors sharing exploited CVEs
How this actor moves through an intrusion, stage by stage, titled by ATT&CK tactic. Read left to right.
1 technique·derived
Profiling frameworks fingerprinting visitors before payload delivery.
2 techniques·derived
Selective exploitation via a large network of impersonated news sites.
1 technique·derived
Registry Run Keys.
2 techniques·derived
Signed antivirus and productivity binaries used as loaders.
1 technique·derived
LLMNR/NBT-NS Poisoning.
2 techniques·derived
DNS, Web Service.
1 technique·derived
Cryptomining deployed as a decoy to misdirect incident responders.
Scroll horizontally · characteristic chain across documented operations, not a single incident
Grouped in kill-chain order.
Profiling frameworks fingerprinting visitors before payload delivery
Selective exploitation via a large network of impersonated news sites
Signed antivirus and productivity binaries used as loaders
Cryptomining deployed as a decoy to misdirect incident responders
Over 100 websites impersonating legitimate Vietnamese news outlets, running profiling frameworks that fingerprinted visitors and delivered payloads only to those matching a target profile — leaving ordinary readers unaffected and the infrastructure difficult to detect externally.
Relationship type and confidence stated explicitly — 'related' without qualification is not an assessment.
Curated links to the reports that established what is known about this group.