Amnesty International reported that Vietnamese human rights defenders and a rights organization were targeted in a coordinated spyware campaign attributed to Ocean Lotus (APT32) between 2018 and 2020. Identified victims included blogger and activist Bui Thanh Hieu, the nonprofit VOICE (Vietnamese Overseas Initiative for Conscience Empowerment), and another Vietnam-based blogger whose identity was withheld for safety reasons. The operation used phishing emails carrying malicious attachments or links, then delivered malware for macOS and Windows while displaying decoy documents to disguise the intrusion.
On Windows systems, the attackers deployed Kerrdown and then Cobalt Strike to expand access and control over compromised devices. The activity fits a broader pattern of reporting on Ocean Lotus operations targeting Vietnamese civil society, media, and other entities, with multiple investigations describing the group as aligned with Vietnamese state interests, although Amnesty said it could not independently prove a direct link to the Vietnamese government. Amnesty said the surveillance campaign formed part of a wider environment of repression, censorship, arrests, harassment, and online restrictions affecting activists in Vietnam, and called for an independent investigation and tighter controls on surveillance technology.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Amnesty International reported that a coordinated spyware campaign targeting Vietnamese human rights defenders and a human rights organization ran from February 2018 through November 2020. The activity used phishing emails with malicious attachments or links to deliver MacOS or Windows malware.
Amnesty International's Security Lab disclosed a coordinated spyware campaign affecting Bui Thanh Hieu, VOICE, and another Vietnamese blogger, and attributed the activity to Ocean Lotus. Amnesty said the campaign deployed Kerrdown and then Cobalt Strike on Windows systems, while noting it could not independently prove a direct link to the Vietnamese government.
Bayerischer Rundfunk published an investigation titled "Lined up in the sights of Vietnamese hackers" about Ocean Lotus activity. The reference provides the publication date but no explicit separate event date beyond the publication itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.