Overview
APT32 (MITRE ATT&CK ID G0050) is a suspected Vietnam-based threat group MITRE ATT&CK documents as active since at least 2014. Per MITRE’s profile, the group has targeted multiple private-sector industries as well as foreign governments, dissidents, and journalists, with a strong focus on Southeast Asian countries including Vietnam, the Philippines, Laos, and Cambodia. MITRE notes the group has extensively used strategic web compromises (watering-hole attacks) to compromise victims.
Known tools and malware (per MITRE ATT&CK relationship data)
Our ingested data links APT32 to malware including Kerrdown, SOUNDBITE, KOMPROGO, PHOREAL, WINDSHIELD, Denis, OSX_OCEANLOTUS.D (a macOS-targeting variant), RotaJakiro, and Goopy, alongside dual-use tools Cobalt Strike, Mimikatz, and standard Windows utilities (ipconfig, netsh, Arp, Net).
Notable techniques (per MITRE ATT&CK relationship data)
Techniques linked to APT32 in our data include Archive Collected Data (T1560), Clear Windows Event Logs (T1685.005), Command Obfuscation (T1027.010), Credentials in Registry (T1552.002), DLL (T1574.001), Domains (T1583.001), and Drive-by Compromise (T1189) — the last consistent with MITRE’s note on the group’s extensive use of strategic web compromises.
What we don’t have
MITRE’s ingested data doesn’t include a first-seen/last-seen activity date range for groups — we report “active since at least 2014” per MITRE’s description text. We have no independent telemetry or IOC data beyond MITRE’s STIX bundle, and no campaign relationships are present for this group in our ingested data.
Frequently Asked Questions
What is APT32? A suspected Vietnam-based threat group, per MITRE ATT&CK, active since at least 2014, known for targeting private industry, dissidents, and journalists across Southeast Asia.
Is APT32 the same as OceanLotus? Yes — MITRE ATT&CK tracks OceanLotus and SeaLotus as aliases of the same group designation.
What techniques does APT32 favor? Per MITRE ATT&CK’s relationship data, drive-by compromise (strategic web/watering-hole attacks) is a documented, extensively used technique for this group, alongside DLL-based persistence and registry-stored credential theft.
Data sourced from MITRE ATT&CK® (https://attack.mitre.org), group ID G0050, aggregated September 14, 2026. This product uses MITRE ATT&CK data but is not endorsed or certified by MITRE. See more threat actor profiles.