G0050

G0050APT32

Description

[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)

References

  1. https://attack.mitre.org/groups/G0050
  2. https://www.amnestyusa.org/wp-content/uploads/2021/02/Click-and-Bait_Vietnamese-Human-Rights-Defenders-Targeted-with-Spyware-Attacks.pdf
  3. https://www.fireeye.com/blog/threat-research/2017/05/cyber-espionage-apt32.html
  4. https://www.cybereason.com/blog/operation-cobalt-kitty-apt
  5. https://www.welivesecurity.com/2019/03/20/fake-or-fake-keeping-up-with-oceanlotus-decoys/
  6. https://www.welivesecurity.com/2018/03/13/oceanlotus-ships-new-backdoor/
  7. https://www.volexity.com/blog/2017/11/06/oceanlotus-blossoms-mass-digital-surveillance-and-exploitation-of-asean-nations-the-media-human-rights-and-civil-society/

Software attributed to this4

TypeTargetConfidenceTier
SoftwareDeniss0354100%live
SoftwareGoopys0477100%live
SoftwareKOMPROGOs0156100%live
SoftwareOSX_OCEANLOTUS.Ds0352100%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Actor
APT30
Group
APT33
Group
APT12
Group
APT17
Group
APT-C-36
Group
APT41
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, SQUR.