Vexday analysis
APT32, também conhecido como OceanLotus, SeaLotus, BISMUTH e Canvas Cyclone (identificador MITRE ATT&CK G0050), é um grupo de ameaça persistente avançada de origem vietnamita ativo pelo menos desde 2014. O grupo tem como alvos múltiplos setores da iniciativa privada, governos estrangeiros, dissidentes e jornalistas, com forte concentração em países do Sudeste Asiático como Vietnã, Filipinas, Laos e Camboja. Entre seus métodos, destaca-se o uso extensivo de comprometimentos estratégicos de sites para atingir vítimas, com 78 técnicas documentadas no MITRE ATT&CK e 2 CVEs atribuídas ao grupo.
Attack chain
Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.
Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).
Techniques (MITRE ATT&CK) 78
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities 2
CVEs this group is known to exploit, per MITRE ATT&CK. Ordered by real-world severity.
Known infrastructure 1295
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
118.196.95.249:8080Cobalt Strikethreatfox116.198.42.177:8081Cobalt Strikethreatfox118.196.95.249:80Cobalt Strikethreatfox118.196.95.249:443Cobalt Strikethreatfox118.196.95.249:22Cobalt Strikethreatfox116.198.42.177:8080Cobalt Strikethreatfox116.198.42.177:443Cobalt Strikethreatfox116.198.42.177:80Cobalt Strikethreatfox116.198.42.177:22Cobalt Strikethreatfox117.72.159.96:9998Cobalt Strikethreatfox43.128.21.190:123Cobalt Strikethreatfox108.165.147.244:18080Cobalt Strikethreatfox47.79.98.75:8080Cobalt Strikethreatfox68.64.182.169:8001Cobalt Strikethreatfox47.79.98.75:80Cobalt Strikethreatfox212.87.199.197:80Cobalt Strikethreatfox212.87.199.197:443Cobalt Strikethreatfox101.43.39.2:88Cobalt Strikethreatfox1.94.145.106:8888Cobalt Strikethreatfox47.79.98.75:443Cobalt Strikethreatfox47.79.98.75:22Cobalt Strikethreatfox212.87.199.197:8080Cobalt Strikethreatfox119.29.122.42:5004Cobalt Strikethreatfox20.187.120.42:8080Cobalt Strikethreatfox20.187.120.42:443Cobalt Strikethreatfox20.187.120.42:80Cobalt Strikethreatfox20.187.120.42:22Cobalt Strikethreatfox43.225.157.17:8088Cobalt Strikethreatfox43.128.21.190:8080Cobalt Strikethreatfox43.128.21.190:8888Cobalt Strikethreatfox+1295 indicators in total. See them all on the IOCs page.
References
APT32 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →