APT32 is a Vietnamese state-affiliated espionage threat actor widely known as OceanLotus and also tracked as Canvas Cyclone, BISMUTH, Cobalt Kitty, SeaLotus, Ocean Buffalo, Lotus Bane, Pond Loach, and several other vendor-specific aliases. The group has conducted long-running cyber espionage operations aligned with Vietnamese strategic interests and has targeted governments, dissidents, journalists, foreign corporations, and organizations in sectors such as finance, telecommunications, transportation, construction, and broader critical or strategically important industries in Southeast Asia and beyond. APT32 is known for combining targeted intrusion tradecraft with custom malware development, social engineering, and supply-chain compromise. Reported operations have included targeting Vietnamese stock investors and infrastructure- and transportation-related companies through a compromised software supply chain associated with FireAnt MetaKit. The group has also been linked to campaigns targeting Chinese cybersecurity professionals and malware analysts. The actor uses a diverse malware ecosystem and loaders, including families such as SPECTRALVIPER, P8LOADER, POWERSEAL, and DONUTLOADER in activity overlapping with OceanLotus. Observed tradecraft includes DLL side-loading, process injection, shellcode staging, masquerading as legitimate software, in-memory evasion of AMSI and ETW, encrypted command-and-control over web protocols, and use of named pipes for local or alternate command channels. APT32 malware has supported capabilities such as PE loading, token theft and impersonation, file upload and download, directory manipulation, and execution of additional payloads. On compromised systems, APT32 has performed extensive host fingerprinting and discovery. Reported behaviors include collecting operating system version and computer name, querying the Windows Registry for system information, and fingerprinting macOS hosts during initial beaconing. The group has also used shellcode to identify infected hostnames. Persistence and configuration storage frequently rely on Windows Registry abuse. APT32 has established persistence through Registry Run keys to launch PowerShell scripts, Visual Basic scripts, and backdoor components, and has modified the Registry to store backdoor configuration data. ATT&CK techniques associated with the group include PowerShell execution, exploitation for privilege escalation, setuid and setgid abuse in Linux-focused emulation and detection mappings, registry-based persistence, registry discovery, and broader command-and-scripting interpreter use. APT32 should be understood as a mature, state-aligned intrusion set with flexible tooling, strong operational security, and a history of adapting delivery and persistence mechanisms to victim environments. Its operations consistently emphasize stealth, post-compromise reconnaissance, durable persistence, and intelligence collection in support of Vietnamese national interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
52 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
34 malware families attributed to this actor across reporting.
29 additional families tracked in Mallory.
6 CVEs this actor has used in observed campaigns. 6 of them exploited in the wild.
APT32 has used CVE-2016-7255 to escalate privileges.
...has exploited Office vulnerabilities such as CVE-2017-11882...
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
The following analytic detects when su runs from a page-cache-corrupted binary... This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access... CVE CVE-2026-31431 ... References ... copy-fail-CVE-2026-31431
1 more CVE tied to this actor tracked in Mallory.
489 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Vietnamese investors and construction-related companies through a supply chain breach and malware deployment.
Vietnamese state-affiliated espionage activity linked to the SPECTRALVIPER intrusion set, targeting strategically important Vietnamese organizations including finance, agribusiness/food-security, and government, using bespoke loaders/backdoors and stealthy in-memory execution.
Listed as an annotation/tag associated with privilege escalation techniques in the detection content; no campaign or activity by the group is described in this reference.
Referenced in the IOC investigation/actor comparison context as a possible actor associated with the observed intrusion artifacts and infrastructure, but the report explicitly states no specific threat-actor records or overlap data were provided and attribution is not established.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.