APT32 is a Vietnam-linked cyber espionage group targeting governments and private sectors across Southeast Asia.
Analyst brief
APT32 is a Vietnam-linked cyber espionage group targeting governments, private sector companies, dissidents, and journalists across Southeast Asia and beyond. Their key TTPs include Spearphishing for initial access, JavaScript execution, Masquerading for stealth, Pass the Hash for lateral movement, and exfiltration over non-standard ports, using tools like Cobalt Strike, Mimikatz, and custom malware such as Kerrdown. Defenders should focus on email security hardening, implementing strict credential protection to prevent Pass the Hash attacks, and monitoring network traffic for anomalous non-C2 protocol data exfiltration.
APT32
OceanLotus GroupOcean LotusOceanLotus
nation-state
Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. FireEye assesses that APT32 leverages a unique suite of fully-featured malware, in conjunction with commercially-available tools, to conduct targeted operations that are aligned with Vietnamese state interests.
origin (suspected)
🇻🇳Vietnam· state-sponsoredattribution confidence: medium (50)