APT32
Also tracked as SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
- Documented techniques
- 78
- Assessed origin
- Vietnam
- First seen
- 2014
- Basis
- MITRE ATT&CK
How they break in
Techniques MITRE has documented this group using, grouped by the stage of an attack they belong to. This is the actionable half: each one is a behaviour you can look for in your own logs, and a control you can test.
reconnaissance3
resource development6
initial access3
execution12
- T1047 Windows Management Instrumentation
- T1053.005 Scheduled Task
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1059.007 JavaScript
- T1072 Software Deployment Tools
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1569.002 Service Execution
persistence4
privilege escalation1
credential access3
discovery10
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1018 Remote System Discovery
- T1033 System Owner/User Discovery
- T1046 Network Service Discovery
- T1049 System Network Connections Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1135 Network Share Discovery
lateral movement4
command and control5
exfiltration2
defense impairment3
stealth20
- T1027.010 Command Obfuscation
- T1027.011 Fileless Storage
- T1027.013 Encrypted/Encoded File
- T1027.016 Junk Code Insertion
- T1036 Masquerading
- T1036.003 Rename Legitimate Utilities
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1055 Process Injection
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1078.003 Local Accounts
- T1216.001 PubPrn
- T1218.005 Mshta
- T1218.010 Regsvr32
- T1218.011 Rundll32
- T1564.001 Hidden Files and Directories
- T1564.003 Hidden Window
- T1564.004 NTFS File Attributes
- T1574.001 DLL
Malware
Families MITRE records this group deploying. Detection names for these are a reasonable place to start.
Tools
Legitimate or dual-use software the group is documented using. Most of it is software your own administrators use too, which is the point.