« All threats

APT groupMITRE G0050

APT32

Also known as: apt 32, apt-32, apt-c-00, atk17, bismuth, canvas cyclone, cobalt kitty, g0050, ocean buffalo, ocean lotus, oceanlotus, oceanlotus group

[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)

Victims in the last 90 days0

Most affected countries

No data yet.

Most affected sectors

No data yet.

Priority mitigations

MITRE ATT&CK mitigations that cover the most techniques used by this group.

  1. Privileged Account Management (15 techniques covered)
  2. Behavior Prevention on Endpoint (15 techniques covered)
  3. Execution Prevention (14 techniques covered)
  4. User Account Management (11 techniques covered)
  5. Network Intrusion Prevention (11 techniques covered)
  6. User Training (10 techniques covered)
  7. Audit (10 techniques covered)
  8. Restrict Web-Based Content (8 techniques covered)

MITRE ATT&CK techniques

T1550.002 · Pass the HashT1036 · MasqueradingT1059.007 · JavaScriptT1047 · Windows Management InstrumentationT1072 · Software Deployment ToolsT1570 · Lateral Tool TransferT1564.004 · NTFS File AttributesT1552.002 · Credentials in RegistryT1055 · Process InjectionT1216.001 · PubPrnT1566.001 · Spearphishing AttachmentT1135 · Network Share DiscoveryT1033 · System Owner/User DiscoveryT1571 · Non-Standard PortT1082 · System Information DiscoveryT1583.001 · DomainsT1012 · Query RegistryT1027.010 · Command ObfuscationT1059.003 · Windows Command ShellT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1574.001 · DLLT1566.002 · Spearphishing LinkT1598.003 · Spearphishing LinkT1087.001 · Local AccountT1059.001 · PowerShellT1003.001 · LSASS MemoryT1046 · Network Service DiscoveryT1608.004 · Drive-by TargetT1041 · Exfiltration Over C2 ChannelT1036.004 · Masquerade Task or ServiceT1078.003 · Local AccountsT1589 · Gather Victim Identity InformationT1070.006 · TimestompT1189 · Drive-by CompromiseT1218.011 · Rundll32T1059 · Command and Scripting InterpreterT1112 · Modify RegistryT1071.003 · Mail ProtocolsT1560 · Archive Collected DataT1204.001 · Malicious LinkT1071.001 · Web ProtocolsT1036.005 · Match Legitimate Resource Name or LocationT1070.004 · File DeletionT1027.011 · Fileless StorageT1105 · Ingress Tool TransferT1053.005 · Scheduled TaskT1036.003 · Rename Legitimate UtilitiesT1543.003 · Windows ServiceT1608.001 · Upload MalwareT1222.002 · Linux and Mac PermissionsT1569.002 · Service ExecutionT1018 · Remote System DiscoveryT1218.005 · MshtaT1083 · File and Directory DiscoveryT1685.005 · Clear Windows Event LogsT1059.005 · Visual BasicT1588.002 · ToolT1021.002 · SMB/Windows Admin SharesT1550.003 · Pass the TicketT1583.006 · Web Services

Recent victims

No data yet.

Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.

Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.