Cyber Threat Actor: APT32
| Actor Type | Location | Known Incidents |
Nation State
|
Viet Nam
|
30 incidents |
|---|
Profile
OceanLotus, also known as APT32 and Cobalt Kitty, is a threat actor publicly linked to the Vietnamese government, with multiple U.S.-based cybersecurity firms attributing its activity to state‑backed actors from Viet Nam. The actor is recognized by the aliases OceanLotus, APT32 and Cobalt Kitty in public reporting and has been observed conducting operations that align with Vietnamese state interests.
The actor’s targeting patterns, as documented in the provided sources, focus on government entities, multinational corporations, media outlets, human rights groups, civil society organizations and regional institutions. Campaigns have been directed at Chinese government bodies managing the coronavirus response, Philippine governmental offices, ASEAN‑related entities such as the ASEAN Trade Repository, and automotive manufacturers including BMW, Hyundai and Toyota. The strategic objectives cited in the reporting are espionage and economic espionage, with actors seeking non‑public information on pandemic response, diplomatic communications, intellectual property for Vietnam’s automotive sector and intelligence on regional political developments.
Observed tactics, techniques and procedures include the use of spearphishing emails delivering METALJACK malware, the deployment of the Cobalt Strike penetration toolkit as a backdoor, and the creation of counterfeit domains that mimic legitimate services such as Google and Facebook to facilitate social engineering. The actor has employed strategic JavaScript injections on compromised websites to modify content and lure victims into installing malware, and has used custom Google applications to hijack Gmail accounts for data exfiltration. Infrastructure elements noted in the reporting include the use of Let’s Encrypt certificates to lend legitimacy to malicious domains, the implementation of whitelists to focus on high‑value targets, and the employment of multiple backdoors beyond Cobalt Strike.
Attribution to a state sponsor is explicitly stated in the sources, with FireEye, Mandiant and other U.S.‑based companies describing OceanLotus/APT32 as a unit attributed to the Vietnamese government. No public attribution to criminal consortia or non‑state actors is presented in the material.
Representative campaigns highlighted in the material include a 2020 spearphishing operation that used COVID‑19‑themed lures and METALJACK malware against China’s Ministry of Emergency Management and Wuhan authorities to gather pandemic‑related intelligence; a 2019 intrusion into BMW and Hyundai networks where Cobalt Strike was used to establish persistent backdoors for suspected intellectual property theft benefitting Vietnam’s automotive industry; a 2017‑2018 campaign that compromised over 100 websites to conduct mass digital surveillance of ASEAN government, media, human rights and civil society targets, leveraging counterfeit domains and custom Google apps; and a 2017 leak of Philippine government documents, including a Trump‑Duterte transcript and related confidential files, which was linked to OceanLotus through forensic artifacts and submitted to VirusTotal. These incidents illustrate the actor’s recurring focus on governmental, diplomatic and industrial targets across Southeast Asia and beyond, employing a consistent set of spearphishing, web‑injection and backdoor techniques to achieve espionage‑oriented objectives.
