Menu
Browse

APT32

Aliases: 2 aliases
Primary URL Location Industry
Undetermined
Country Viet Nam
Technology Icon
Technology
Profile

APT32, also known as Ocean Lotus, is a Vietnam‑based threat group that conducts cyber espionage and digital surveillance operations. Headquartered in Viet Nam, the group focuses on infiltrating government entities, military organisations, human rights advocates, civil society groups, and media outlets across multiple Asian nations and the broader ASEAN region. Its activities are characterised by the creation of malicious infrastructure that mimics legitimate online services to facilitate data collection and victim profiling.

The group’s operational scale is evidenced by the compromise of over 100 websites, which were used to host fraudulent pages resembling platforms such as Google and Facebook. These sites served as vectors for delivering JavaScript‑based social engineering lures and for deploying custom Google Apps designed to hijack Gmail accounts. APT32 relies on a distributed hosting infrastructure, employs spoofed domains, and leverages Let’s Encrypt certificates to appear trustworthy while maintaining persistence.

Distinguishing attributes of APT32 include its precise targeting methodology, which utilises whitelists to select specific victims, and its use of exclusive backdoors such as Cobalt Strike to exfiltrate sensitive communications. The group’s ability to conduct large‑scale victim profiling and to sustain long‑term access demonstrates a notable level of technical sophistication and organisational focus on espionage rather than financially motivated cybercrime.

A documented incident from January 1 2015 illustrates these capabilities, as Ocean Lotus launched a widespread digital surveillance campaign that targeted numerous sectors across Asia, employing the described techniques to steal confidential information and monitor adversaries. This event, along with the group’s persistent activity under the aliases APT32 and Ocean Lotus, underscores its role as a sophisticated state‑aligned cyber threat originating from Viet Nam.

Incidents
Linked incidents available to members
1 incident