All actors

APT32

Also reported as OceanLotus, Canvas Cyclone, SeaLotus, APT-C-00, BISMUTH and 18 other names. Linked to Vietnam by four sources.

Reports
849
Last reported
Known CVEs
362
Techniques in ATT&CK
78
Origin
Vietnam
ID
G0050
Merge evidence
34 alias matches

Reports per quarter

  1. 2007 Q4: 1 report
  2. 2008 Q1: no reports
  3. 2008 Q2: no reports
  4. 2008 Q3: no reports
  5. 2008 Q4: no reports
  6. 2009 Q1: no reports
  7. 2009 Q2: no reports
  8. 2009 Q3: no reports
  9. 2009 Q4: no reports
  10. 2010 Q1: no reports
  11. 2010 Q2: no reports
  12. 2010 Q3: no reports
  13. 2010 Q4: no reports
  14. 2011 Q1: no reports
  15. 2011 Q2: no reports
  16. 2011 Q3: no reports
  17. 2011 Q4: no reports
  18. 2012 Q1: no reports
  19. 2012 Q2: no reports
  20. 2012 Q3: no reports
  21. 2012 Q4: no reports
  22. 2013 Q1: no reports
  23. 2013 Q2: no reports
  24. 2013 Q3: no reports
  25. 2013 Q4: no reports
  26. 2014 Q1: 1 report
  27. 2014 Q2: no reports
  28. 2014 Q3: 1 report
  29. 2014 Q4: no reports
  30. 2015 Q1: no reports
  31. 2015 Q2: 1 report
  32. 2015 Q3: no reports
  33. 2015 Q4: no reports
  34. 2016 Q1: 3 reports
  35. 2016 Q2: no reports
  36. 2016 Q3: 3 reports
  37. 2016 Q4: no reports
  38. 2017 Q1: 1 report
  39. 2017 Q2: 16 reports
  40. 2017 Q3: no reports
  41. 2017 Q4: 6 reports
  42. 2018 Q1: 5 reports
  43. 2018 Q2: 11 reports
  44. 2018 Q3: 3 reports
  45. 2018 Q4: 7 reports
  46. 2019 Q1: 13 reports
  47. 2019 Q2: 26 reports
  48. 2019 Q3: 8 reports
  49. 2019 Q4: 8 reports
  50. 2020 Q1: 16 reports
  51. 2020 Q2: 26 reports
  52. 2020 Q3: 23 reports
  53. 2020 Q4: 56 reports
  54. 2021 Q1: 54 reports
  55. 2021 Q2: 62 reports
  56. 2021 Q3: 66 reports
  57. 2021 Q4: 55 reports
  58. 2022 Q1: 58 reports
  59. 2022 Q2: 68 reports
  60. 2022 Q3: 50 reports
  61. 2022 Q4: 16 reports
  62. 2023 Q1: 17 reports
  63. 2023 Q2: 12 reports
  64. 2023 Q3: 17 reports
  65. 2023 Q4: 15 reports
  66. 2024 Q1: 6 reports
  67. 2024 Q2: 11 reports
  68. 2024 Q3: 20 reports
  69. 2024 Q4: 12 reports
  70. 2025 Q1: 9 reports
  71. 2025 Q2: 8 reports
  72. 2025 Q3: 9 reports
  73. 2025 Q4: 4 reports
  74. 2026 Q1: 4 reports
  75. 2026 Q2: 40 reports
  76. 2026 Q3: 1 report
Dated reports, 2007 Q4 to 2026 Q3.

Techniques seen in the last two years

Show all 288 techniques Show fewer

Counts come from technique IDs in the actor's report text. “Reports only” means reports name the technique but MITRE ATT&CK® does not list it for this actor.

Also listed by ATT&CK

Show all 18 techniques Show fewer

CVEs named in reports

Show all 362 CVEs Show fewer

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

Show all 849 reports Show fewer
  1. Threat Group Cards: A Threat Actor Encyclopedia

    date ORKL added it fromORKL

  2. METALJACK (Malware Family)

    date ORKL added it fromORKL

  3. Cobalt Strike (Malware Family)

    date ORKL added it fromORKL

  4. BlackSuit Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  5. How Microsoft names threat actors

    date in the title fromORKL

  6. BumbleBee: Round Two

    publisher's date The DFIR Report fromORKLDFIR Report

  7. RedSense

    Malpedia library date fromORKL

  8. APT trends report Q2 2020

    date in the title fromORKL

  9. RedSense

    Malpedia library date fromORKL

  10. CERT-UA

    Malpedia library date fromORKL

  11. CERT-UA

    Malpedia library date fromORKL

  12. RedSense

    Malpedia library date fromORKL

  13. yir-cyber-threats-annex-download.pdf

    Malpedia library date fromORKL

  14. Stairwell threat report - The origin of APT32 macros

    Malpedia library date Stairwell fromORKLCCS '25 data

  15. Quantum Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  16. RedSense

    Malpedia library date fromORKL

  17. CERT-UA

    Malpedia library date fromORKL

  18. 2021 Year In Review

    publisher's date The DFIR Report fromORKLDFIR Report

  19. 2021trends.pdf

    Malpedia library date fromORKL

  20. RedSense

    Malpedia library date fromORKL

  21. Abusing Microsoft Office Using Malicious Web Archive Files

    date in the title fromORKL

  22. Nickel

    Malpedia library date Notice of Pleadings fromORKLCCS '25 data

  23. From Zero to Domain Admin

    publisher's date The DFIR Report fromORKLDFIR Report

  24. Global_APT_Research_Report_for_the_first_half_of_2021-360

    file creation date fromORKL

  25. RedSense

    Malpedia library date fromORKL

  26. Microsoft Digital Defense Report OCTOBER 2021

    file creation date fromORKL

  27. report-old-dogs-new-tricks.pdf

    Malpedia library date fromORKL

  28. Ryuk Ransomware Now Targeting Webservers

    Malpedia library date fromORKL

  29. Geopolitical nation-state threat actor overview June 2021

    date in the title fromORKL

  30. mtrends-2018.pdf

    file creation date fromORKL

  31. Conti Ransomware

    publisher's date The DFIR Report fromORKLDFIR Report

  32. CTIR_casestudy_2.pdf

    file creation date fromORKL

  33. RotaJakiro, the Linux version of the OceanLotus

    date in the title fromORKL

  34. CTIR_casestudy_1.pdf

    file creation date fromORKL

  35. the-operations-of-winnti-group.pdf

    Malpedia library date fromORKL

  36. mtrends-2021

    file creation date fromORKL

  37. report-bb-2021-threat-report.pdf

    Malpedia library date fromORKL

  38. Technical Analysis of Operation Diànxùn

    Malpedia library date fromORKL

  39. Bazar Drops the Anchor

    publisher's date The DFIR Report fromORKLDFIR Report

  40. amnesty.org-Click and Bait Vietnamese Human Rights Defenders Targeted with Spyware Attacks

    date in the CCS '25 data Amnesty International fromORKLCCS '25 data

  41. The_CrowdStrike_2021_Global_Threat_Report

    file creation date fromORKL

  42. Bazar, No Ryuk?

    publisher's date The DFIR Report fromORKLDFIR Report

  43. Objective-See's Blog

    file creation date fromORKL

  44. Active Directory 侵害と推奨対策

    Malpedia library date fromORKL

  45. Analyzing Cobalt Strike for Fun and Profit

    date in the title fromORKL

  46. Taking Action Against Hackers in Bangladesh and Vietnam

    date in the title fromORKL

  47. New MacOS Backdoor Connected to OceanLotus Surfaces

    date in the title fromORKL

  48. OceanLotus Continues With Its Cyber Espionage Operations

    date in the title fromORKL

  49. OceanLotus_ Extending Cyber Espionage Operations Through Fake Websites _ Volexity

    date in the CCS '25 data Volexity fromORKLCCS '25 data

  50. Ryuk in 5 Hours

    publisher's date The DFIR Report fromORKLDFIR Report

  51. Blood_Rubia_APT_CN_version

    date in the CCS '25 data QiAnXin fromORKLCCS '25 data

  52. Ryuk's Return

    publisher's date The DFIR Report fromORKLDFIR Report

  53. Release the Kraken_ Fileless APT attack abuses Windows Error Reporting service

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  54. 69da886eecc7087e9dac2d3ea4c66ba8

    file creation date fromORKL

  55. APT_trends_report_Q2_2020_Securelist

    file creation date fromORKL

  56. APT trends report Q2 2020

    date in the title fromORKL

  57. Hijacking DLLs in Windows

    date in the title fromORKL

  58. Targeted Attack Leverages India-China Border Dispute

    date in the CCS '25 data Zscaler fromORKLCCS '25 data

  59. 210527.pdf

    Malpedia library date FBI fromORKLCCS '25 data

  60. T1055 Process Injection

    date in the title fromORKL

  61. Oceanlotus.xlsx

    Malpedia library date fromORKL

  62. Hiding in plain sight- PhantomLance walks into a market

    date in the title fromORKL

  63. Ursnif via LOLbins

    publisher's date The DFIR Report fromORKLDFIR Report

  64. 200407-MWB-COVID-White-Paper_Final

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  65. Catching APT41 exploiting a zero-day vulnerability

    date in the CCS '25 data Darktrace fromCCS '25 data

  66. Report2020CrowdStrikeGlobalThreatReport

    Malpedia library date fromORKL

  67. Aarhus_miniseminar_291118.pdf

    Malpedia library date fromORKL

  68. mobile-malware-report.pdf

    file creation date fromORKL

  69. Analytics

    Malpedia library date fromORKL

  70. Operation-Taskmasters-2019-eng

    date in the CCS '25 data Positive Technologies fromORKLCCS '25 data

  71. New Network Vermin from OceanLotus

    date in the CCS '25 data Cylance fromORKLCCS '25 data

  72. OceanLotus

    file creation date fromORKL

  73. Hunting and detecting Cobalt Strike

    date in the title fromORKL

  74. Thưởng tết….

    date in the title fromORKL

  75. OceanLotus Attacks to Indochinese Peninsula

    date in the CCS '25 data QiAnXin fromORKLCCS '25 data

  76. Deobfuscating APT32 Flow Graphs with Cutter and Radare2

    date in the title fromORKL

  77. Funky malware format found in Ocean Lotus sample

    date in the CCS '25 data Malwarebytes fromORKLCCS '25 data

  78. OceanLotus Steganography Malware Analysis White Paper

    Malpedia library date Cylance fromORKLCCS '25 data

  79. Collection of helper scripts for OceanLotus

    date in the title fromORKL

  80. OceanLotus- macOS malware update

    date in the title fromORKL

  81. Lotus Blossom Continues ASEAN Targeting

    file creation date fromORKL

  82. Report- OceanLotus APT Group Leveraging Steganography

    date in the title fromORKL

  83. Blog | Arctic Wolf

    Malpedia library date Cylance fromORKLCCS '25 data

  84. mpressioncss_ta_report_2019.pdf

    Malpedia library date fromORKL

  85. JEShell- An OceanLotus (APT32) Backdoor

    date in the title fromORKL

  86. 2019.01.03.Tencent_APT_Summary_report_2018_CN_Version

    file creation date fromORKL

  87. 2018 Master Table

    file creation date fromORKL

  88. OceanLotus_KerrDown

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  89. Tracking OceanLotus’ new Downloader, KerrDown

    date in the title fromORKL

  90. Pond Loach delivers BadCake malware

    date in the title fromORKL

  91. Là 1937CN hay OceanLotus hay Lazarus …

    date in the title fromORKL

  92. The SpyRATs of OceanLotus Malware Analysis White Paper

    file creation date fromORKL

  93. Volatility Plugin for Detecting Cobalt Strike Beacon

    date in the title fromORKL

  94. Latest observed JS payload used for APT32 profiling.

    Malpedia library date Github (9b) fromORKLCCS '25 data

  95. M-Trends Overview

    Malpedia library date Marco Rottigni fromORKL

  96. [CN]_OceanLotus_new_malware

    date in the CCS '25 data Tencent fromORKLCCS '25 data

  97. M-TRENDS2018

    file creation date FireEye fromORKL

  98. New MacOS Backdoor Linked to OceanLotus Found

    date in the title fromORKL

  99. ESET_OceanLotus

    Malpedia library date fromORKL

  100. Lotus Blossom Continues ASEAN Targeting

    date in the title fromORKL

  101. apt32-continues-asean-targeting

    date in the CCS '25 data RSA fromORKLCCS '25 data

  102. APT32

    date in the title fromORKL

  103. The New and Improved macOS Backdoor from OceanLotus

    date in the title fromORKL

  104. The New and Improved macOS Backdoor from OceanLotus - Palo Alto Networks Blog

    date in the CCS '25 data Palo Alto fromORKLCCS '25 data

  105. Operation Cobalt Kitty Threat Actor Profile & IOC

    date in the CCS '25 data Cybereason fromORKLCCS '25 data

  106. APT32- New Cyber Espionage Group

    date in the title fromORKL

  107. 摩诃草组织

    file creation date fromORKL

  108. 人面狮行动

    date in the CCS '25 data F-Secure fromORKLCCS '25 data

  109. 人面狮行动

    date in the CCS '25 data Kaspersky fromORKLCCS '25 data

  110. OS X Malware Samples Analyzed

    date in the title fromORKL

  111. 2015年中国高持续性威胁(APT)研究报告

    file creation date fromORKL

  112. Oceanlotus

    date in the CCS '25 data SkyEye fromORKLCCS '25 data

Newest first. Details opens the report in Explore.