APT32
Also known as: apt 32, apt-32, apt-c-00, atk17, bismuth, canvas cyclone, cobalt kitty, g0050, ocean buffalo, ocean lotus, oceanlotus, oceanlotus group
[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)
Most affected countries
No data yet.
Most affected sectors
No data yet.
Priority mitigations
MITRE ATT&CK mitigations that cover the most techniques used by this group.
- Privileged Account Management (15 techniques covered)
- Behavior Prevention on Endpoint (15 techniques covered)
- Execution Prevention (14 techniques covered)
- User Account Management (11 techniques covered)
- Network Intrusion Prevention (11 techniques covered)
- User Training (10 techniques covered)
- Audit (10 techniques covered)
- Restrict Web-Based Content (8 techniques covered)
MITRE ATT&CK techniques
Recent victims
No data yet.
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.