APT32
Also tracked as SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
- Known attack methods
- 78
- Origin
- Vietnam
- First seen
- 2014
- Source
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, mapped onto the ATT&CK matrix. Each one is a behaviour you can look for in your own logs, and a control you can test.
Reconnaissance
12 techniques · 2 used
Resource Development
9 techniques · 4 used
Initial Access
11 techniques · 2 used
Execution
20 techniques · 7 used
Persistence
22 techniques · 4 used
Privilege Escalation
13 techniques · 1 used
Stealth
30 techniques · 9 used
Defense Impairment
18 techniques · 3 used
Credential Access
17 techniques · 2 used
Discovery
34 techniques · 10 used
Lateral Movement
9 techniques · 3 used
Collection
17 techniques · 2 used
Command and Control
18 techniques · 4 used
Exfiltration
9 techniques · 2 used
Impact
15 techniques
Reconnaissance3
Resource development6
Execution12
- T1047Windows Management Instrumentation
- T1053.005Scheduled Task
- T1059Command and Scripting Interpreter
- T1059.001PowerShell
- T1059.003Windows Command Shell
- T1059.005Visual Basic
- T1059.007JavaScript
- T1072Software Deployment Tools
- T1203Exploitation for Client Execution
- T1204.001Malicious Link
- T1204.002Malicious File
- T1569.002Service Execution
Persistence4
Privilege escalation1
Stealth20
- T1027.010Command Obfuscation
- T1027.011Fileless Storage
- T1027.013Encrypted/Encoded File
- T1027.016Junk Code Insertion
- T1036Masquerading
- T1036.003Rename Legitimate Utilities
- T1036.004Masquerade Task or Service
- T1036.005Match Legitimate Resource Name or Location
- T1055Process Injection
- T1070.004File Deletion
- T1070.006Timestomp
- T1078.003Local Accounts
- T1216.001PubPrn
- T1218.005Mshta
- T1218.010Regsvr32
- T1218.011Rundll32
- T1564.001Hidden Files and Directories
- T1564.003Hidden Window
- T1564.004NTFS File Attributes
- T1574.001DLL
Defense impairment3
Discovery10
- T1012Query Registry
- T1016System Network Configuration Discovery
- T1018Remote System Discovery
- T1033System Owner/User Discovery
- T1046Network Service Discovery
- T1049System Network Connections Discovery
- T1082System Information Discovery
- T1083File and Directory Discovery
- T1087.001Local Account
- T1135Network Share Discovery
Lateral movement4
Command and control5
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.