APT32
Aliases: SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
Open interactive actor investigation
ATT&CK techniques
T1550.002
Pass the HashT1036
MasqueradingT1059.007
JavaScriptT1047
Windows Management InstrumentationT1072
Software Deployment ToolsT1570
Lateral Tool TransferT1564.004
NTFS File AttributesT1552.002
Credentials in RegistryT1055
Process InjectionT1216.001
PubPrnT1566.001
Spearphishing AttachmentT1135
Network Share DiscoveryT1033
System Owner/User DiscoveryT1571
Non-Standard PortT1082
System Information DiscoveryT1583.001
DomainsT1012
Query RegistryT1027.010
Command ObfuscationT1059.003
Windows Command ShellT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1574.002
DLL Side-LoadingT1566.002
Spearphishing LinkT1598.003
Spearphishing LinkT1087.001
Local AccountT1059.001
PowerShellT1003.001
LSASS MemoryT1046
Network Service DiscoveryT1608.004
Drive-by TargetT1041
Exfiltration Over C2 ChannelT1036.004
Masquerade Task or ServiceT1003
OS Credential DumpingT1078.003
Local AccountsT1589
Gather Victim Identity InformationT1070.006
TimestompT1189
Drive-by CompromiseT1218.011
Rundll32T1059
Command and Scripting InterpreterT1112
Modify RegistryT1071.003
Mail ProtocolsT1560
Archive Collected DataT1204.001
Malicious LinkT1071.001
Web ProtocolsT1036.005
Match Legitimate Name or LocationT1070.004
File DeletionT1070.001
Clear Windows Event LogsT1027.011
Fileless StorageT1105
Ingress Tool TransferT1053.005
Scheduled TaskT1036.003
Rename System UtilitiesT1543.003
Windows ServiceT1608.001
Upload MalwareT1222.002
Linux and Mac File and Directory Permissions ModificationT1569.002
Service ExecutionT1018
Remote System DiscoveryT1218.005
MshtaT1083
File and Directory DiscoveryT1059.005
Visual BasicT1588.002
ToolT1021.002
SMB/Windows Admin SharesT1550.003
Pass the TicketT1583.006
Web ServicesT1505.003
Web ShellT1564.001
Hidden Files and DirectoriesT1016
System Network Configuration DiscoveryT1027.001
Binary PaddingT1049
System Network Connections DiscoveryT1564.003
Hidden WindowT1027.013
Encrypted/Encoded FileT1056.001
KeyloggingT1589.002
Email AddressesT1218.010
Regsvr32T1068
Exploitation for Privilege EscalationT1585.001
Social Media AccountsT1137
Office Application StartupT1203
Exploitation for Client ExecutionT1204.002
Malicious FileT1547.001
Registry Run Keys / Startup FolderT1102
Web ServiceT1087
Account Discovery
Pass the HashT1036
MasqueradingT1059.007
JavaScriptT1047
Windows Management InstrumentationT1072
Software Deployment ToolsT1570
Lateral Tool TransferT1564.004
NTFS File AttributesT1552.002
Credentials in RegistryT1055
Process InjectionT1216.001
PubPrnT1566.001
Spearphishing AttachmentT1135
Network Share DiscoveryT1033
System Owner/User DiscoveryT1571
Non-Standard PortT1082
System Information DiscoveryT1583.001
DomainsT1012
Query RegistryT1027.010
Command ObfuscationT1059.003
Windows Command ShellT1048.003
Exfiltration Over Unencrypted Non-C2 ProtocolT1574.002
DLL Side-LoadingT1566.002
Spearphishing LinkT1598.003
Spearphishing LinkT1087.001
Local AccountT1059.001
PowerShellT1003.001
LSASS MemoryT1046
Network Service DiscoveryT1608.004
Drive-by TargetT1041
Exfiltration Over C2 ChannelT1036.004
Masquerade Task or ServiceT1003
OS Credential DumpingT1078.003
Local AccountsT1589
Gather Victim Identity InformationT1070.006
TimestompT1189
Drive-by CompromiseT1218.011
Rundll32T1059
Command and Scripting InterpreterT1112
Modify RegistryT1071.003
Mail ProtocolsT1560
Archive Collected DataT1204.001
Malicious LinkT1071.001
Web ProtocolsT1036.005
Match Legitimate Name or LocationT1070.004
File DeletionT1070.001
Clear Windows Event LogsT1027.011
Fileless StorageT1105
Ingress Tool TransferT1053.005
Scheduled TaskT1036.003
Rename System UtilitiesT1543.003
Windows ServiceT1608.001
Upload MalwareT1222.002
Linux and Mac File and Directory Permissions ModificationT1569.002
Service ExecutionT1018
Remote System DiscoveryT1218.005
MshtaT1083
File and Directory DiscoveryT1059.005
Visual BasicT1588.002
ToolT1021.002
SMB/Windows Admin SharesT1550.003
Pass the TicketT1583.006
Web ServicesT1505.003
Web ShellT1564.001
Hidden Files and DirectoriesT1016
System Network Configuration DiscoveryT1027.001
Binary PaddingT1049
System Network Connections DiscoveryT1564.003
Hidden WindowT1027.013
Encrypted/Encoded FileT1056.001
KeyloggingT1589.002
Email AddressesT1218.010
Regsvr32T1068
Exploitation for Privilege EscalationT1585.001
Social Media AccountsT1137
Office Application StartupT1203
Exploitation for Client ExecutionT1204.002
Malicious FileT1547.001
Registry Run Keys / Startup FolderT1102
Web ServiceT1087
Account Discovery