APT32
APT32, also known as OceanLotus, Ocean Lotus, APT-C-00, BISMUTH, Cobalt Kitty, Canvas Cyclone, Lotus Bane, Ocean Buffalo, Pond Loach, SeaLotus, SectorF01, and TIN Woodlawn, is a Vietnam-aligned cyberespionage threat actor whose operations are described as aligned with the interests of the Vietnamese government. Reporting in the provided content states the group has been active since at least 2012, with Amnesty International noting activity since at least 2014. The group has targeted Vietnamese human rights defenders and civil society, the private sector, domestic Vietnamese entities, stock investors, foreign governments including Laos and Cambodia, NGOs, news agencies, and businesses across sectors including information technology, hospitality, agriculture and commodities, hospitals, retail, automotive, and mobile services. The content describes APT32 using spearphishing attachments to lure users into executing a malicious dropper, hosting payloads on Dropbox, Amazon S3, and Google Drive, and using JavaScript over HTTP or HTTPS to attacker-controlled domains to download additional frameworks and encrypted payloads. It has used COM scriptlets to download Cobalt Strike beacons, heavily obfuscated PowerShell including the WindowStyle parameter to hide execution, Invoke-Obfuscation, and regsvr32.exe "Squiblydoo" to retrieve second-stage payloads. For persistence, APT32 modified Windows Services to ensure PowerShell scripts were loaded and created a Windows service; it also used Registry Run keys to execute PowerShell, VBS scripts, and its backdoor directly. The group has used WMI to deploy tools on remote machines and gather information about the Outlook process. Observed discovery behavior includes listing files and directories, collecting victim usernames, executing whoami, gathering IP configuration with ipconfig /all, and using shellcode to collect usernames. The content also notes a macOS backdoor that hides a clientID file via chflags, and Amnesty International reported OceanLotus malware for both Windows and macOS. In the Amnesty-reported campaign, Windows infections used Kerrdown, described there as used exclusively by OceanLotus, to download additional spyware including Cobalt Strike, while the macOS malware allowed access to system information and supported file download, upload, execution, and command execution. Recent reporting in the provided content attributes two SPECTRALVIPER campaigns to OceanLotus/APT32. One targeted a Vietnamese infrastructure and transport construction corporation from late 2024 to February 2026, likely involving remote code execution vulnerabilities in Microsoft SQL Server and DLL side-loading. The second was a supply-chain attack from October 2025 to March 2026 against FireAnt MetaKit, a platform used by stock investors in Vietnam, in which the group abused the legitimate update URL to selectively deliver SPECTRALVIPER. The malware is described as supporting host reconnaissance, HTTPS-based command and control, orchestration, lateral movement via named pipes, and process injection, including execution in OneDrive.Sync.Service.exe. The reporting characterizes these campaigns as reflecting an increasing emphasis on domestic espionage inside Vietnam.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
57 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
29 malware families attributed to this actor across reporting.
24 additional families tracked in Mallory.
Associated vulnerabilities
4 CVEs this actor has used in observed campaigns. 4 of them exploited in the wild.
APT32 has used CVE-2016-7255 to escalate privileges.
...has exploited Office vulnerabilities such as CVE-2017-11882...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
Observables
316 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducted two espionage-focused campaigns in Vietnam: one targeting a Vietnamese infrastructure and transport construction corporation, and another supply chain attack abusing FireAnt Metakit updates to deliver the SPECTRALVIPER backdoor to stock investors. The activity indicates a shift toward domestic espionage targets.
Conducted a supply chain attack against FireAnt MetaKit to selectively deliver the SPECTRALVIPER backdoor to stock investors in Vietnam, with apparent surveillance objectives tied to domestic financial investigations.
Conducted cyber espionage campaigns targeting domestic Vietnamese entities and stock investors, including a supply chain attack via FireAnt Metakit and a prolonged intrusion into a Vietnamese infrastructure and transport construction corporation. The group is described as shifting toward domestic espionage while maintaining a history of targeting China and Vietnamese civil society, media, and dissidents.
Cyberespionage group conducting selective external operations and increasing domestic espionage in Vietnam from 2024 to 2026, including a supply-chain attack via FireAnt MetaKit targeting stock investors and a prolonged intrusion into a Vietnamese infrastructure and transport construction company.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.