APT32

APT / StateG0050
Origin🇻🇳 Vietnã
Techniques (MITRE ATT&CK)78
SourceMITRE ATT&CK
State sponsor: VietnamAttribution confidence: 50%Target categories: Government, Private sector, Civil society
Targeted regions: China · Germany · United States · Vietnam · Philippines · Association of Southeast Asian Nations
Also known as:SeaLotusOceanLotusAPT-C-00Canvas CycloneBISMUTH

Vexday analysis

APT32, também conhecido como OceanLotus, SeaLotus, BISMUTH e Canvas Cyclone (identificador MITRE ATT&CK G0050), é um grupo de ameaça persistente avançada de origem vietnamita ativo pelo menos desde 2014. O grupo tem como alvos múltiplos setores da iniciativa privada, governos estrangeiros, dissidentes e jornalistas, com forte concentração em países do Sudeste Asiático como Vietnã, Filipinas, Laos e Camboja. Entre seus métodos, destaca-se o uso extensivo de comprometimentos estratégicos de sites para atingir vítimas, com 78 técnicas documentadas no MITRE ATT&CK e 2 CVEs atribuídas ao grupo.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity84
Impact: High
T1189T1047T1137T1068T1021.002T1056.001ENTRYInitial accessDrive-byCompromiseEXECExecutionWindows ManagementInstrumentationPERSPersistenceOffice ApplicationStartupPRIVPrivilege escalationExploitation forPrivilege Escalat…LATLateral movementSMB/Windows AdminSharesCOLLCollectionKeyloggingEXFILExfiltrationExfiltration OverC2 Channel

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Techniques (MITRE ATT&CK) 78

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities 2

CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.

Known infrastructure 1295

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port118.196.95.249:8080Cobalt Strikethreatfox
ip:port116.198.42.177:8081Cobalt Strikethreatfox
ip:port118.196.95.249:80Cobalt Strikethreatfox
ip:port118.196.95.249:443Cobalt Strikethreatfox
ip:port118.196.95.249:22Cobalt Strikethreatfox
ip:port116.198.42.177:8080Cobalt Strikethreatfox
ip:port116.198.42.177:443Cobalt Strikethreatfox
ip:port116.198.42.177:80Cobalt Strikethreatfox
ip:port116.198.42.177:22Cobalt Strikethreatfox
ip:port117.72.159.96:9998Cobalt Strikethreatfox
ip:port43.128.21.190:123Cobalt Strikethreatfox
ip:port108.165.147.244:18080Cobalt Strikethreatfox
ip:port47.79.98.75:8080Cobalt Strikethreatfox
ip:port68.64.182.169:8001Cobalt Strikethreatfox
ip:port47.79.98.75:80Cobalt Strikethreatfox
ip:port212.87.199.197:80Cobalt Strikethreatfox
ip:port212.87.199.197:443Cobalt Strikethreatfox
ip:port101.43.39.2:88Cobalt Strikethreatfox
ip:port1.94.145.106:8888Cobalt Strikethreatfox
ip:port47.79.98.75:443Cobalt Strikethreatfox
ip:port47.79.98.75:22Cobalt Strikethreatfox
ip:port212.87.199.197:8080Cobalt Strikethreatfox
ip:port119.29.122.42:5004Cobalt Strikethreatfox
ip:port20.187.120.42:8080Cobalt Strikethreatfox
ip:port20.187.120.42:443Cobalt Strikethreatfox
ip:port20.187.120.42:80Cobalt Strikethreatfox
ip:port20.187.120.42:22Cobalt Strikethreatfox
ip:port43.225.157.17:8088Cobalt Strikethreatfox
ip:port43.128.21.190:8080Cobalt Strikethreatfox
ip:port43.128.21.190:8888Cobalt Strikethreatfox

+1295 indicators in total. See them all on the IOCs page.

APT32 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →