APT32
Also reported as OceanLotus, Canvas Cyclone, SeaLotus, APT-C-00, BISMUTH and 18 other names. Linked to Vietnam by four sources.
Reports per quarter
Techniques seen in the last two years
- T1057 11 reports reports only
- T1053.005 9 reports in ATT&CK
- T1082 9 reports in ATT&CK
- T1105 9 reports in ATT&CK
- T1059.003 8 reports in ATT&CK
- T1016 7 reports in ATT&CK
- T1027 7 reports reports only
- T1033 7 reports in ATT&CK
- T1059.001 7 reports in ATT&CK
- T1018 6 reports in ATT&CK
Show all 288 techniques Show fewer
- T1047 6 reports in ATT&CK
- T1083 6 reports in ATT&CK
- T1140 6 reports reports only
- T1190 6 reports reports only
- T1219 6 reports reports only
- T1041 5 reports in ATT&CK
- T1053 5 reports reports only
- T1059 5 reports in ATT&CK
- T1068 5 reports in ATT&CK
- T1071.001 5 reports in ATT&CK
- T1136.001 5 reports reports only
- T1204.002 5 reports in ATT&CK
- T1543.003 5 reports in ATT&CK
- T1566.001 5 reports in ATT&CK
- T1003.001 4 reports in ATT&CK
- T1005 4 reports reports only
- T1012 4 reports in ATT&CK
- T1021.001 4 reports reports only
- T1036 4 reports in ATT&CK
- T1059.005 4 reports in ATT&CK
- T1069.002 4 reports reports only
- T1071 4 reports reports only
- T1087.002 4 reports reports only
- T1136 4 reports reports only
- T1189 4 reports in ATT&CK
- T1204 4 reports reports only
- T1482 4 reports reports only
- T1566 4 reports reports only
- T1572 4 reports reports only
- T1007 3 reports reports only
- T1021.002 3 reports in ATT&CK
- T1036.005 3 reports in ATT&CK
- T1046 3 reports in ATT&CK
- T1048 3 reports reports only
- T1049 3 reports in ATT&CK
- T1055 3 reports in ATT&CK
- T1055.002 3 reports reports only
- T1070 3 reports reports only
- T1070.004 3 reports in ATT&CK
- T1078 3 reports reports only
- T1087.001 3 reports in ATT&CK
- T1112 3 reports in ATT&CK
- T1129 3 reports reports only
- T1132.001 3 reports reports only
- T1135 3 reports in ATT&CK
- T1486 3 reports reports only
- T1497 3 reports reports only
- T1505.003 3 reports in ATT&CK
- T1518.001 3 reports reports only
- T1543.004 3 reports reports only
- T1547.001 3 reports in ATT&CK
- T1555.003 3 reports reports only
- T1569 3 reports reports only
- T1570 3 reports in ATT&CK
- T1573 3 reports reports only
- T1574.001 3 reports in ATT&CK
- T1003 2 reports in ATT&CK
- T1003.002 2 reports reports only
- T1003.003 2 reports reports only
- T1008 2 reports reports only
- T1021 2 reports reports only
- T1027.009 2 reports reports only
- T1055.004 2 reports reports only
- T1056.001 2 reports in ATT&CK
- T1059.006 2 reports reports only
- T1059.007 2 reports in ATT&CK
- T1069.001 2 reports reports only
- T1071.004 2 reports reports only
- T1078.002 2 reports reports only
- T1090 2 reports reports only
- T1090.001 2 reports reports only
- T1095 2 reports reports only
- T1098 2 reports reports only
- T1098.007 2 reports reports only
- T1104 2 reports reports only
- T1119 2 reports reports only
- T1124 2 reports reports only
- T1133 2 reports reports only
- T1134.001 2 reports reports only
- T1134.002 2 reports reports only
- T1203 2 reports in ATT&CK
- T1217 2 reports reports only
- T1218.007 2 reports reports only
- T1222 2 reports reports only
- T1496 2 reports reports only
- T1505.004 2 reports reports only
- T1529 2 reports reports only
- T1543.001 2 reports reports only
- T1546.015 2 reports reports only
- T1548 2 reports reports only
- T1553 2 reports reports only
- T1559 2 reports reports only
- T1560 2 reports in ATT&CK
- T1560.001 2 reports reports only
- T1564 2 reports reports only
- T1566.002 2 reports in ATT&CK
- T1566.004 2 reports reports only
- T1567 2 reports reports only
- T1569.002 2 reports in ATT&CK
- T1571 2 reports in ATT&CK
- T1573.001 2 reports reports only
- T1573.002 2 reports reports only
- T1583 2 reports reports only
- T1583.001 2 reports in ATT&CK
- T1583.003 2 reports reports only
- T1583.004 2 reports reports only
- T1587.001 2 reports reports only
- T1590 2 reports reports only
- T1595 2 reports reports only
- T1595.002 2 reports reports only
- T1598 2 reports reports only
- T1608 2 reports reports only
- T1608.001 2 reports in ATT&CK
- T1608.002 2 reports reports only
- T1608.006 2 reports reports only
- T1620 2 reports reports only
- T1649 2 reports reports only
- T1010 1 report reports only
- T1016.001 1 report reports only
- T1020 1 report reports only
- T1021.004 1 report reports only
- T1021.005 1 report reports only
- T1021.006 1 report reports only
- T1027.001 1 report reports only
- T1027.003 1 report reports only
- T1027.007 1 report reports only
- T1027.013 1 report in ATT&CK
- T1036.003 1 report in ATT&CK
- T1036.004 1 report in ATT&CK
- T1036.008 1 report reports only
- T1037 1 report reports only
- T1037.001 1 report reports only
- T1039 1 report reports only
- T1040 1 report reports only
- T1053.003 1 report reports only
- T1055.001 1 report reports only
- T1055.003 1 report reports only
- T1055.009 1 report reports only
- T1055.012 1 report reports only
- T1056 1 report reports only
- T1059.002 1 report reports only
- T1059.004 1 report reports only
- T1059.009 1 report reports only
- T1059.010 1 report reports only
- T1059.011 1 report reports only
- T1069 1 report reports only
- T1069.003 1 report reports only
- T1072 1 report in ATT&CK
- T1074 1 report reports only
- T1074.001 1 report reports only
- T1074.002 1 report reports only
- T1078.003 1 report in ATT&CK
- T1078.004 1 report reports only
- T1087 1 report reports only
- T1087.004 1 report reports only
- T1090.003 1 report reports only
- T1091 1 report reports only
- T1098.001 1 report reports only
- T1098.003 1 report reports only
- T1098.004 1 report reports only
- T1098.005 1 report reports only
- T1098.006 1 report reports only
- T1102 1 report in ATT&CK
- T1102.002 1 report reports only
- T1113 1 report reports only
- T1114 1 report reports only
- T1114.001 1 report reports only
- T1114.002 1 report reports only
- T1114.003 1 report reports only
- T1115 1 report reports only
- T1120 1 report reports only
- T1123 1 report reports only
- T1125 1 report reports only
- T1132 1 report reports only
- T1134 1 report reports only
- T1136.002 1 report reports only
- T1137 1 report in ATT&CK
- T1137.006 1 report reports only
- T1195 1 report reports only
- T1195.001 1 report reports only
- T1195.002 1 report reports only
- T1199 1 report reports only
- T1200 1 report reports only
- T1201 1 report reports only
- T1204.001 1 report in ATT&CK
- T1204.004 1 report reports only
- T1210 1 report reports only
- T1213 1 report reports only
- T1213.001 1 report reports only
- T1213.002 1 report reports only
- T1213.003 1 report reports only
- T1218.011 1 report in ATT&CK
- T1484 1 report reports only
- T1484.001 1 report reports only
- T1485 1 report reports only
- T1489 1 report reports only
- T1490 1 report reports only
- T1491.002 1 report reports only
- T1497.001 1 report reports only
- T1497.003 1 report reports only
- T1498 1 report reports only
- T1505 1 report reports only
- T1518 1 report reports only
- T1526 1 report reports only
- T1528 1 report reports only
- T1530 1 report reports only
- T1534 1 report reports only
- T1537 1 report reports only
- T1538 1 report reports only
- T1539 1 report reports only
- T1543 1 report reports only
- T1543.002 1 report reports only
- T1546 1 report reports only
- T1546.003 1 report reports only
- T1546.004 1 report reports only
- T1546.008 1 report reports only
- T1546.012 1 report reports only
- T1547 1 report reports only
- T1547.002 1 report reports only
- T1547.005 1 report reports only
- T1547.009 1 report reports only
- T1548.002 1 report reports only
- T1550 1 report reports only
- T1550.001 1 report reports only
- T1550.002 1 report in ATT&CK
- T1552 1 report reports only
- T1554 1 report reports only
- T1555 1 report reports only
- T1556 1 report reports only
- T1556.006 1 report reports only
- T1556.009 1 report reports only
- T1558.003 1 report reports only
- T1559.001 1 report reports only
- T1560.002 1 report reports only
- T1563.002 1 report reports only
- T1564.004 1 report in ATT&CK
- T1565 1 report reports only
- T1565.001 1 report reports only
- T1566.003 1 report reports only
- T1567.001 1 report reports only
- T1567.002 1 report reports only
- T1574 1 report reports only
- T1574.011 1 report reports only
- T1578 1 report reports only
- T1580 1 report reports only
- T1583.006 1 report in ATT&CK
- T1584 1 report reports only
- T1584.004 1 report reports only
- T1585 1 report reports only
- T1585.002 1 report reports only
- T1586.002 1 report reports only
- T1587 1 report reports only
- T1587.003 1 report reports only
- T1588 1 report reports only
- T1588.002 1 report in ATT&CK
- T1588.003 1 report reports only
- T1588.004 1 report reports only
- T1588.007 1 report reports only
- T1589.002 1 report in ATT&CK
- T1590.005 1 report reports only
- T1592 1 report reports only
- T1595.001 1 report reports only
- T1602 1 report reports only
- T1602.001 1 report reports only
- T1602.002 1 report reports only
- T1608.003 1 report reports only
- T1608.004 1 report in ATT&CK
- T1608.005 1 report reports only
- T1613 1 report reports only
- T1614 1 report reports only
- T1614.001 1 report reports only
- T1615 1 report reports only
- T1619 1 report reports only
- T1621 1 report reports only
- T1622 1 report reports only
- T1652 1 report reports only
- T1654 1 report reports only
- T1657 1 report reports only
Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.
Also listed by ATT&CK
CVEs named in reports
- CVE-2007-5633
- CVE-2008-2463
- CVE-2008-3431 KEV
- CVE-2009-0824
- CVE-2009-0927 KEV
- CVE-2009-3129 KEV
- CVE-2010-0188 KEV ransomware
- CVE-2010-0232 KEV
- CVE-2010-0249 KEV
- CVE-2010-1592
- CVE-2010-3333 KEV
- CVE-2010-4398 KEV
Show all 362 CVEs Show fewer
- CVE-2011-0609 KEV
- CVE-2011-0611 KEV
- CVE-2011-2005 KEV
- CVE-2011-2110
- CVE-2011-3544 KEV
- CVE-2011-4369
- CVE-2012-0151 KEV
- CVE-2012-0158 KEV ransomware
- CVE-2012-0422
- CVE-2012-0779
- CVE-2012-1535 KEV
- CVE-2012-1723 KEV ransomware
- CVE-2012-1856 KEV
- CVE-2012-1875
- CVE-2012-1889 KEV
- CVE-2012-4681 KEV ransomware
- CVE-2012-4792 KEV
- CVE-2012-5687
- CVE-2013-0422 KEV ransomware
- CVE-2013-0634
- CVE-2013-0808
- CVE-2013-1331 KEV
- CVE-2013-1347 KEV
- CVE-2013-1493
- CVE-2013-2618
- CVE-2013-2729 KEV
- CVE-2013-3346 KEV
- CVE-2013-3660 KEV
- CVE-2013-3893 KEV
- CVE-2013-3897 KEV
- CVE-2013-3900 KEV
- CVE-2013-3906 KEV
- CVE-2013-4979
- CVE-2013-5065 KEV
- CVE-2013-5947
- CVE-2013-7331 KEV
- CVE-2014-0160 KEV
- CVE-2014-0322 KEV
- CVE-2014-0497 KEV
- CVE-2014-0515
- CVE-2014-1225
- CVE-2014-1761 KEV
- CVE-2014-1776 KEV
- CVE-2014-1812 KEV ransomware
- CVE-2014-2962
- CVE-2014-4019
- CVE-2014-4076
- CVE-2014-4113 KEV
- CVE-2014-4114 KEV
- CVE-2014-6332 KEV
- CVE-2014-6352 KEV
- CVE-2014-8361 KEV
- CVE-2014-8439 KEV
- CVE-2014-9583
- CVE-2015-0097
- CVE-2015-0554
- CVE-2015-1641 KEV
- CVE-2015-1642 KEV
- CVE-2015-1701 KEV ransomware
- CVE-2015-1805
- CVE-2015-2291 KEV ransomware
- CVE-2015-2387 KEV
- CVE-2015-2419 KEV
- CVE-2015-2424 KEV
- CVE-2015-2545 KEV
- CVE-2015-2546 KEV ransomware
- CVE-2015-2590 KEV
- CVE-2015-3043 KEV
- CVE-2015-3105
- CVE-2015-4902 KEV
- CVE-2015-5119 KEV
- CVE-2015-5122 KEV
- CVE-2015-6585
- CVE-2015-7248
- CVE-2015-7254
- CVE-2015-7645 KEV ransomware
- CVE-2015-7755 KEV
- CVE-2015-8651 KEV
- CVE-2016-0034 KEV ransomware
- CVE-2016-0167 KEV ransomware
- CVE-2016-0189 KEV ransomware
- CVE-2016-1019 KEV ransomware
- CVE-2016-10401
- CVE-2016-3353
- CVE-2016-4117 KEV ransomware
- CVE-2016-4119
- CVE-2016-4171 KEV
- CVE-2016-7255 KEV ransomware
- CVE-2016-7855 KEV
- CVE-2017-0143 KEV ransomware
- CVE-2017-0144 KEV ransomware
- CVE-2017-0146 KEV ransomware
- CVE-2017-0147 KEV ransomware
- CVE-2017-0176
- CVE-2017-0199 KEV ransomware
- CVE-2017-01992
- CVE-2017-0213 KEV ransomware
- CVE-2017-0261 KEV
- CVE-2017-0262 KEV
- CVE-2017-0263 KEV
- CVE-2017-1000353 KEV
- CVE-2017-10271 KEV ransomware
- CVE-2017-1099
- CVE-2017-11317 KEV
- CVE-2017-11357 KEV ransomware
- CVE-2017-11467
- CVE-2017-11774 KEV
- CVE-2017-1182
- CVE-2017-11882 KEV ransomware
- CVE-2017-12149 KEV ransomware
- CVE-2017-12629
- CVE-2017-12824
- CVE-2017-15399
- CVE-2017-15944 KEV
- CVE-2017-17215
- CVE-2017-5638 KEV ransomware
- CVE-2017-5689 KEV
- CVE-2017-6327 KEV
- CVE-2017-6328
- CVE-2017-7269 KEV
- CVE-2017-8291 KEV
- CVE-2017-8570 KEV
- CVE-2017-8759 KEV
- CVE-2017-9248 KEV
- CVE-2017-9805 KEV
- CVE-2017-9822 KEV ransomware
- CVE-2018-0101
- CVE-2018-0171 KEV
- CVE-2018-0296 KEV
- CVE-2018-0798 KEV
- CVE-2018-0802 KEV ransomware
- CVE-2018-0824 KEV
- CVE-2018-10088
- CVE-2018-10561 KEV
- CVE-2018-10562 KEV ransomware
- CVE-2018-11776 KEV
- CVE-2018-1207
- CVE-2018-13379 KEV ransomware
- CVE-2018-15454
- CVE-2018-15961 KEV
- CVE-2018-15982 KEV ransomware
- CVE-2018-20250 KEV ransomware
- CVE-2018-2628 KEV
- CVE-2018-2893
- CVE-2018-4878 KEV ransomware
- CVE-2018-4990 KEV
- CVE-2018-5002 KEV
- CVE-2018-7600 KEV ransomware
- CVE-2018-7602 KEV ransomware
- CVE-2018-8120 KEV ransomware
- CVE-2018-8174 KEV ransomware
- CVE-2018-8373 KEV
- CVE-2018-8453 KEV ransomware
- CVE-2018-8581 KEV ransomware
- CVE-2018-8589 KEV
- CVE-2018-8611 KEV
- CVE-2018-8639 KEV ransomware
- CVE-2018-8641
- CVE-2018-8653 KEV
- CVE-2018-9866
- CVE-2019-0604 KEV ransomware
- CVE-2019-0708 KEV ransomware
- CVE-2019-0803 KEV ransomware
- CVE-2019-10149 KEV
- CVE-2019-11510 KEV ransomware
- CVE-2019-11580 KEV ransomware
- CVE-2019-1322 KEV ransomware
- CVE-2019-1367 KEV ransomware
- CVE-2019-13720 KEV
- CVE-2019-1405 KEV ransomware
- CVE-2019-1429 KEV
- CVE-2019-1458 KEV ransomware
- CVE-2019-1579 KEV ransomware
- CVE-2019-16098
- CVE-2019-1652 KEV
- CVE-2019-1653 KEV
- CVE-2019-16920 KEV
- CVE-2019-17026 KEV
- CVE-2019-18935 KEV ransomware
- CVE-2019-19781 KEV ransomware
- CVE-2019-2725 KEV ransomware
- CVE-2019-3396 KEV ransomware
- CVE-2019-3398 KEV
- CVE-2019-5591 KEV ransomware
- CVE-2019-7609 KEV
- CVE-2019-8394 KEV
- CVE-2019-9621 KEV
- CVE-2019-9670 KEV
- CVE-2020-0601 KEV
- CVE-2020-0674 KEV
- CVE-2020-0688 KEV ransomware
- CVE-2020-0787 KEV ransomware
- CVE-2020-0796 KEV ransomware
- CVE-2020-0986 KEV
- CVE-2020-10189 KEV
- CVE-2020-10198
- CVE-2020-1040 KEV
- CVE-2020-116511
- CVE-2020-11652 KEV
- CVE-2020-11899 KEV
- CVE-2020-12641 KEV
- CVE-2020-1350 KEV
- CVE-2020-1380 KEV
- CVE-2020-1472 KEV ransomware
- CVE-2020-1472122
- CVE-2020-14750 KEV
- CVE-2020-14882 KEV
- CVE-2020-1599
- CVE-2020-1664
- CVE-2020-17144 KEV
- CVE-2020-2021 KEV ransomware
- CVE-2020-3125
- CVE-2020-3529
- CVE-2020-35730 KEV
- CVE-2020-4006 KEV
- CVE-2020-5135 KEV ransomware
- CVE-2020-5902 KEV ransomware
- CVE-2020-6789
- CVE-2020-7961 KEV
- CVE-2020-8243 KEV
- CVE-2020-8260 KEV
- CVE-2020-8515 KEV
- CVE-2021-1636
- CVE-2021-1675 KEV ransomware
- CVE-2021-1732 KEV ransomware
- CVE-2021-1844
- CVE-2021-1879 KEV
- CVE-2021-20016 KEV ransomware
- CVE-2021-21148 KEV
- CVE-2021-2114810
- CVE-2021-21166 KEV
- CVE-2021-21972 KEV ransomware
- CVE-2021-22894 KEV
- CVE-2021-22899 KEV
- CVE-2021-22900 KEV
- CVE-2021-26084 KEV ransomware
- CVE-2021-26411 KEV ransomware
- CVE-2021-2641111
- CVE-2021-26855 KEV ransomware
- CVE-2021-26857 KEV ransomware
- CVE-2021-26858 KEV ransomware
- CVE-2021-26868
- CVE-2021-27065 KEV ransomware
- CVE-2021-27857
- CVE-2021-27876 KEV ransomware
- CVE-2021-27877 KEV ransomware
- CVE-2021-27878 KEV ransomware
- CVE-2021-29855
- CVE-2021-30116 KEV ransomware
- CVE-2021-30551 KEV
- CVE-2021-30665 KEV
- CVE-2021-30666 KEV
- CVE-2021-31195
- CVE-2021-31196 KEV
- CVE-2021-31206
- CVE-2021-31207 KEV ransomware
- CVE-2021-3156 KEV
- CVE-2021-31979 KEV
- CVE-2021-3197961
- CVE-2021-33742 KEV
- CVE-2021-33771 KEV
- CVE-2021-3377162
- CVE-2021-34448 KEV
- CVE-2021-344486
- CVE-2021-34473 KEV ransomware
- CVE-2021-34523 KEV ransomware
- CVE-2021-34527 KEV ransomware
- CVE-2021-35211 KEV ransomware
- CVE-2021-35464 KEV ransomware
- CVE-2021-36798
- CVE-2021-36934 KEV
- CVE-2021-36942 KEV ransomware
- CVE-2021-40444 KEV ransomware
- CVE-2021-40449 KEV ransomware
- CVE-2021-40539 KEV ransomware
- CVE-2021-4104
- CVE-2021-41379 KEV ransomware
- CVE-2021-44026 KEV
- CVE-2021-44077 KEV
- CVE-2021-44207 KEV
- CVE-2021-44228 KEV ransomware
- CVE-2021-44515 KEV
- CVE-2021-44832
- CVE-2021-45046 KEV ransomware
- CVE-2021-45105
- CVE-2022-21587 KEV ransomware
- CVE-2022-21882 KEV ransomware
- CVE-2022-22954 KEV ransomware
- CVE-2022-22957
- CVE-2022-22958
- CVE-2022-24500
- CVE-2022-24521 KEV ransomware
- CVE-2022-24682 KEV ransomware
- CVE-2022-24934
- CVE-2022-26134 KEV ransomware
- CVE-2022-26809
- CVE-2022-26923 KEV
- CVE-2022-27924 KEV ransomware
- CVE-2022-27925 KEV ransomware
- CVE-2022-30190 KEV ransomware
- CVE-2022-30333 KEV ransomware
- CVE-2022-31199 KEV ransomware
- CVE-2022-37042 KEV ransomware
- CVE-2022-41080 KEV ransomware
- CVE-2022-41082 KEV ransomware
- CVE-2022-42475 KEV ransomware
- CVE-2022-47966 KEV ransomware
- CVE-2022-47986 KEV ransomware
- CVE-2023-0669 KEV ransomware
- CVE-2023-20198 KEV
- CVE-2023-21746
- CVE-2023-22518 KEV ransomware
- CVE-2023-22527 KEV ransomware
- CVE-2023-23397 KEV
- CVE-2023-24880 KEV ransomware
- CVE-2023-27350 KEV ransomware
- CVE-2023-27532 KEV ransomware
- CVE-2023-27997 KEV ransomware
- CVE-2023-28461 KEV ransomware
- CVE-2023-2868 KEV
- CVE-2023-32315 KEV
- CVE-2023-34362 KEV ransomware
- CVE-2023-3466
- CVE-2023-3467
- CVE-2023-3519 KEV ransomware
- CVE-2023-36033 KEV
- CVE-2023-38831 KEV ransomware
- CVE-2023-42793 KEV ransomware
- CVE-2023-45727 KEV
- CVE-2023-46805 KEV ransomware
- CVE-2023-48788 KEV ransomware
- CVE-2023-4966 KEV ransomware
- CVE-2024-0012 KEV ransomware
- CVE-2024-21887 KEV ransomware
- CVE-2024-21893 KEV ransomware
- CVE-2024-21983
- CVE-2024-24919 KEV ransomware
- CVE-2024-27956
- CVE-2024-30051 KEV ransomware
- CVE-2024-3400 KEV ransomware
- CVE-2024-36401 KEV
- CVE-2024-42009 KEV
- CVE-2024-4577 KEV ransomware
- CVE-2024-47575 KEV
- CVE-2024-6473
- CVE-2024-9474 KEV ransomware
- CVE-2025-2783 KEV
- CVE-2025-31324 KEV ransomware
- CVE-2025-55182 KEV ransomware
- CVE-2026-21236
KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.
Reports
Show all 849 reports Show fewer
-
Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor METALJACK (Malware Family)
-
APT 32, OceanLotus, SeaLotus - Threat Group Cards: A Threat Actor Encyclopedia
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor APT 32, OceanLotus, SeaLotus - Threat Group Cards: A Threat Actor Encyclopedia
-
The title opens Wayback Machine, not the publisher’s page. Archived copy on ORKL Detailsfor Obfuscation in the Wild: Targeted Attackers Lead the Way in Evasion Techniques « Threat Research Blog
-
Cobalt Strike (Malware Family)
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Cobalt Strike (Malware Family)
-
Digital Accessibility & Cybersecurity in Healthcare » Blue Sky Calgary
The original link failed its last check. Original publisher Detailsfor Digital Accessibility & Cybersecurity in Healthcare » Blue Sky Calgary
-
Team46 and TaxOff: two sides of the same coin
The original link failed its last check. Original publisher Detailsfor Team46 and TaxOff: two sides of the same coin
-
How Microsoft names threat actors
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Microsoft names threat actors
-
Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
The original link failed its last check. Original publisher Detailsfor Eu_Repo_C_APT_profile_Conti_Wizard_Spider_dc2a733e18.pdf
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation (Đường chín đoạn) typhoon- the cyber sea lotus coveting the nine-dash line in the South China Sea
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Russian Ransomware C2 Network Discovered in Censys Data
The original link failed its last check. Original publisher Detailsfor Russian Ransomware C2 Network Discovered in Censys Data
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
The original link failed its last check. Original publisher Detailsfor THALES%20THREAT%20HANDBOOK%202022%20Light%20Version_1.pdf
-
Hiding in Plain Sight- Obscuring C2s by Abusing CDN Services
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hiding in Plain Sight- Obscuring C2s by Abusing CDN Services
-
yir-cyber-threats-annex-download.pdf
The original link failed its last check. Original publisher Detailsfor yir-cyber-threats-annex-download.pdf
-
Stairwell threat report - The origin of APT32 macros
The original link failed its last check. Original publisher Detailsfor Stairwell threat report - The origin of APT32 macros
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
PHOREAL Malware Targets the Southeast Asian Financial Sector
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor PHOREAL Malware Targets the Southeast Asian Financial Sector
-
Legitimate Sites used as Cobalt Strike C2s against Indian Government
The original link failed its last check. Original publisher Detailsfor Legitimate Sites used as Cobalt Strike C2s against Indian Government
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor 2021trends.pdf
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
VMware Exposing Malware In Linux Based Multi Cloud Environments
The original link failed its last check. Original publisher Detailsfor VMware Exposing Malware In Linux Based Multi Cloud Environments
-
Abusing Microsoft Office Using Malicious Web Archive Files
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Abusing Microsoft Office Using Malicious Web Archive Files
-
Winnti is Coming - Evolution after Prosecution@HITCON2021
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Winnti is Coming - Evolution after Prosecution@HITCON2021
-
Global_APT_Research_Report_for_the_first_half_of_2021-360
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Global_APT_Research_Report_for_the_first_half_of_2021-360
-
sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
The original link failed its last check. Original publisher Detailsfor sneak-peek-ch1-2-finding-beacons-in-the-dark.pdf
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
Masters of Mimicry: new APT group ChamelGang and its arsenal
The original link failed its last check. Original publisher Detailsfor Masters of Mimicry: new APT group ChamelGang and its arsenal
-
The original link failed its last check. Original publisher Detailsfor RedSense
-
Microsoft Digital Defense Report OCTOBER 2021
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Microsoft Digital Defense Report OCTOBER 2021
-
APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT Cobalt Strike Campaign targeting Slovakia (DEF CON talk)
-
Detecting Cobalt Strike- Government-Sponsored Threat Groups (APT32)
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Detecting Cobalt Strike- Government-Sponsored Threat Groups (APT32)
-
report-old-dogs-new-tricks.pdf
The original link failed its last check. Original publisher Detailsfor report-old-dogs-new-tricks.pdf
-
Ryuk Ransomware Now Targeting Webservers
The original link failed its last check. Original publisher Detailsfor Ryuk Ransomware Now Targeting Webservers
-
Geopolitical nation-state threat actor overview June 2021
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Geopolitical nation-state threat actor overview June 2021
-
Looks like the page you're looking for doesn't exist or has moved.
The original link failed its last check. Original publisher Detailsfor Looks like the page you're looking for doesn't exist or has moved.
-
The original link failed its last check. Original publisher Detailsfor mtrends-2018.pdf
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_2.pdf
-
RotaJakiro, the Linux version of the OceanLotus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor RotaJakiro, the Linux version of the OceanLotus
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor CTIR_casestudy_1.pdf
-
the-operations-of-winnti-group.pdf
The original link failed its last check. Original publisher Detailsfor the-operations-of-winnti-group.pdf
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor mtrends-2021
-
report-bb-2021-threat-report.pdf
The original link failed its last check. Original publisher Detailsfor report-bb-2021-threat-report.pdf
-
Technical Analysis of Operation Diànxùn
The original link failed its last check. Original publisher Detailsfor Technical Analysis of Operation Diànxùn
-
Overview of Ocean Lotus Samples used to target Vietnamese Human Rights Defenders
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Overview of Ocean Lotus Samples used to target Vietnamese Human Rights Defenders
-
amnesty.org-Click and Bait Vietnamese Human Rights Defenders Targeted with Spyware Attacks
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor amnesty.org-Click and Bait Vietnamese Human Rights Defenders Targeted with Spyware Attacks
-
The_CrowdStrike_2021_Global_Threat_Report
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The_CrowdStrike_2021_Global_Threat_Report
-
How Vietnam-based hacking operation OceanLotus targets journalists
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor How Vietnam-based hacking operation OceanLotus targets journalists
-
Higaisa or Winnti? APT41 backdoors, old and new
The original link failed its last check. Original publisher Detailsfor Higaisa or Winnti? APT41 backdoors, old and new
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Objective-See's Blog
-
The Mac Malware of 2020 - a comprehensive analysis of the year's new malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The Mac Malware of 2020 - a comprehensive analysis of the year's new malware
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Active Directory 侵害と推奨対策
-
Analyzing Cobalt Strike for Fun and Profit
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Analyzing Cobalt Strike for Fun and Profit
-
Taking Action Against Hackers in Bangladesh and Vietnam
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Taking Action Against Hackers in Bangladesh and Vietnam
-
Tactics, Techniques and Procedures (TTPs) Utilized by FireEye’s Red Team Tools
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tactics, Techniques and Procedures (TTPs) Utilized by FireEye’s Red Team Tools
-
APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT32 Multi-stage macOS Trojan Innovates on Crimeware Scripting Technique
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them - Microsoft Security
-
Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat actor leverages coin miner techniques to stay under the radar – here’s how to spot them
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat actor (BISMUTH) leverages coin miner techniques to stay under the radar – here’s how to spot them
-
New MacOS Backdoor Connected to OceanLotus Surfaces
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New MacOS Backdoor Connected to OceanLotus Surfaces
-
OceanLotus Continues With Its Cyber Espionage Operations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Continues With Its Cyber Espionage Operations
-
Pulse Report: New APT32 Malware Campaign Targets Cambodian Government
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Pulse Report: New APT32 Malware Campaign Targets Cambodian Government
-
OceanLotus_ Extending Cyber Espionage Operations Through Fake Websites _ Volexity
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus_ Extending Cyber Espionage Operations Through Fake Websites _ Volexity
-
Incident readiness: preparing a proactive response to attacks
The original link failed its last check. Original publisher Detailsfor Incident readiness: preparing a proactive response to attacks
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Blood_Rubia_APT_CN_version
-
Release the Kraken_ Fileless APT attack abuses Windows Error Reporting service
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Release the Kraken_ Fileless APT attack abuses Windows Error Reporting service
-
69da886eecc7087e9dac2d3ea4c66ba8
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 69da886eecc7087e9dac2d3ea4c66ba8
-
APT_trends_report_Q2_2020_Securelist
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor APT_trends_report_Q2_2020_Securelist
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT trends report Q2 2020
-
In-Memory shellcode decoding to evade AVs/EDRs
The original link failed its last check. Original publisher Detailsfor In-Memory shellcode decoding to evade AVs/EDRs
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hijacking DLLs in Windows
-
Targeted Attack Leverages India-China Border Dispute
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Targeted Attack Leverages India-China Border Dispute
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor T1055 Process Injection
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Oceanlotus.xlsx
-
Hiding in plain sight- PhantomLance walks into a market
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hiding in plain sight- PhantomLance walks into a market
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Vietnamese Threat Actors APT32 Targeting Wuhan Government and Chinese Ministry of Emergency Management in Latest Example of COVID-19 Related Espionage
-
200407-MWB-COVID-White-Paper_Final
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 200407-MWB-COVID-White-Paper_Final
-
Catching APT41 exploiting a zero-day vulnerability
The original link failed its last check. Detailsfor Catching APT41 exploiting a zero-day vulnerability
-
Storm Cloud Unleashed- Tibetan Focus of Highly Targeted Fake Flash Campaign
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Storm Cloud Unleashed- Tibetan Focus of Highly Targeted Fake Flash Campaign
-
Report2020CrowdStrikeGlobalThreatReport
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Report2020CrowdStrikeGlobalThreatReport
-
Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Uncovering DRBControl: Inside the Cyberespionage Campaign Targeting Gambling Operations
-
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor [CB19] Cyber Threat Landscape in Japan – Revealing Threat in the Shadow by Chi En Shen (Ashley) Oleg Bondarenko
-
The original link failed its last check. Original publisher Detailsfor Aarhus_miniseminar_291118.pdf
-
TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor TA2101 plays government imposter to distribute malware to German, Italian, and US organizations
-
The original link failed its last check. Original publisher Detailsfor mobile-malware-report.pdf
-
Digital Crackdown- Large-Scale Surveillance and Exploitation of Uyghurs
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Digital Crackdown- Large-Scale Surveillance and Exploitation of Uyghurs
-
The original link failed its last check. Original publisher Detailsfor Analytics
-
Operation-Taskmasters-2019-eng
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation-Taskmasters-2019-eng
-
New Network Vermin from OceanLotus
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New Network Vermin from OceanLotus
-
Threat Spotlight- Ratsnif - New Network Vermin from OceanLotus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Threat Spotlight- Ratsnif - New Network Vermin from OceanLotus
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus
-
Hunting and detecting Cobalt Strike
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Hunting and detecting Cobalt Strike
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Thưởng tết….
-
OceanLotus Attacks to Indochinese Peninsula
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Attacks to Indochinese Peninsula
-
Deobfuscating APT32 Flow Graphs with Cutter and Radare2
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Deobfuscating APT32 Flow Graphs with Cutter and Radare2
-
Funky malware format found in Ocean Lotus sample
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Funky malware format found in Ocean Lotus sample
-
OceanLotus Steganography Malware Analysis White Paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Steganography Malware Analysis White Paper
-
Collection of helper scripts for OceanLotus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Collection of helper scripts for OceanLotus
-
OceanLotus- macOS malware update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus- macOS malware update
-
Lotus Blossom Continues ASEAN Targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Lotus Blossom Continues ASEAN Targeting
-
Report- OceanLotus APT Group Leveraging Steganography
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Report- OceanLotus APT Group Leveraging Steganography
-
mpressioncss_ta_report_2019.pdf
The original link failed its last check. Original publisher Detailsfor mpressioncss_ta_report_2019.pdf
-
JEShell- An OceanLotus (APT32) Backdoor
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor JEShell- An OceanLotus (APT32) Backdoor
-
2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2018 Master Table
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus_KerrDown
-
Tracking OceanLotus’ new Downloader, KerrDown
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Tracking OceanLotus’ new Downloader, KerrDown
-
Pond Loach delivers BadCake malware
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Pond Loach delivers BadCake malware
-
Là 1937CN hay OceanLotus hay Lazarus …
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Là 1937CN hay OceanLotus hay Lazarus …
-
The SpyRATs of OceanLotus Malware Analysis White Paper
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The SpyRATs of OceanLotus Malware Analysis White Paper
-
Volatility Plugin for Detecting Cobalt Strike Beacon
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Volatility Plugin for Detecting Cobalt Strike Beacon
-
Latest observed JS payload used for APT32 profiling.
The title opens a link whose publisher is not confirmed. Archived copy on ORKL Detailsfor Latest observed JS payload used for APT32 profiling.
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor [CN]_OceanLotus_new_malware
-
New MacOS Backdoor Linked to OceanLotus Found - TrendLabs Security Intelligence Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor New MacOS Backdoor Linked to OceanLotus Found - TrendLabs Security Intelligence Blog
-
Operation Cobalt Kitty: A large-scale APT in Asia carried out by the OceanLotus Group
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Cobalt Kitty: A large-scale APT in Asia carried out by the OceanLotus Group
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations « Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations | FireEye Inc
-
New MacOS Backdoor Linked to OceanLotus Found
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor New MacOS Backdoor Linked to OceanLotus Found
-
New MacOS Backdoor Linked to OceanLotus Found
The original link failed its last check. Original publisher Detailsfor New MacOS Backdoor Linked to OceanLotus Found
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor ESET_OceanLotus
-
Lotus Blossom Continues ASEAN Targeting
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Lotus Blossom Continues ASEAN Targeting
-
OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN
-
apt32-continues-asean-targeting
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor apt32-continues-asean-targeting
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT32
-
Interesting disguise employed by new Mac malware HiddenLotus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Interesting disguise employed by new Mac malware HiddenLotus
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society | Volexity
-
Operation Cobalt Kitty: A large-scale APT in Asia carried out by the OceanLotus Group
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Cobalt Kitty: A large-scale APT in Asia carried out by the OceanLotus Group
-
The New and Improved macOS Backdoor from OceanLotus
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor The New and Improved macOS Backdoor from OceanLotus
-
The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog
-
Operation Cobalt Kitty- A large-scale APT in Asia carried out by the OceanLotus Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Operation Cobalt Kitty- A large-scale APT in Asia carried out by the OceanLotus Group
-
Operation Cobalt Kitty Threat Actor Profile & IOC
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Operation Cobalt Kitty Threat Actor Profile & IOC
-
APT32- New Cyber Espionage Group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor APT32- New Cyber Espionage Group
-
Ocean Lotus Group-APT 32 identified as Vietnamese APT group
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Ocean Lotus Group-APT 32 identified as Vietnamese APT group
-
Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations
The link to Mirror on Box failed its last check. Mirror on Box Detailsfor Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations
-
Cyber Espionage is Alive and Well- APT32 and the Threat to Global Corporations
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor Cyber Espionage is Alive and Well- APT32 and the Threat to Global Corporations
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 摩诃草组织
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 人面狮行动
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 人面狮行动
-
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OS X Malware Samples Analyzed
-
OceanLotus for OS X – an Application Bundle Pretending to be an Adobe Flash Update
The title opens Mirror on VX-Underground, not the publisher’s page. Archived copy on ORKL Detailsfor OceanLotus for OS X – an Application Bundle Pretending to be an Adobe Flash Update
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor 2015年中国高持续性威胁(APT)研究报告
-
The title opens CyberMonitor archive on GitHub, not the publisher’s page. Archived copy on ORKL Detailsfor Oceanlotus
Newest first. Details opens the report in Explore.