Cyber espionage actors, now designated by FireEye as APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multip...

Threat Actor Profile

APT32

State-sponsored threat group originating from VN. Suspected sponsor: Vietnam. Known to target Government, Private sector, Civil society. Uses 105 known MITRE ATT&CK techniques.

105 TTPs Mapped 3 Industries Tracked Real-Time Alerts

Actor Overview

Origin Country
VN
Suspected Sponsor
Vietnam
Incident Types
Espionage
Known Techniques
105 TTPs

Target Industries

GovernmentPrivate sectorCivil society

Suspected Victims

ChinaGermanyUnited StatesVietnamPhilippinesAssociation of Southeast Asian Nations

MITRE ATT&CK Techniques

T1564.004T1574T1588T1087T1087.001T1583T1583.001T1583.006T1071T1071.001T1071.003T1560T1547T1547.001T1059 +90 more

Related Threat Reports

Premium
APT Campaign Analysis - Q4 2025Dec 2025
New Tactics Observed in WildDec 2025
Infrastructure Mapping ReportDec 2025
Stay Updated

Get alerts when new intel on APT32 is published.

Actor Details

Primary Name
APT32
Known Aliases
OceanLotus Group, Ocean Lotus, OceanLotus, Cobalt Kitty, APT-C-00, SeaLotus, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, BISMUTH, ATK17, G0050, Canvas Cyclone
Data Source
Precursor Intelligence
Need API Access?

Integrate threat actor data into your SIEM or SOAR.

View Plans →