OceanLotus (also tracked as APT32) conducted a broad cyber-espionage campaign targeting critics of the Vietnamese state, journalists, human rights activists, NGOs, foreign governments, hospitals, businesses, and media organizations. Reporting tied the group to spear-phishing, watering-hole attacks, malicious websites, fake news portals, social media personas, shortened links, malicious Android apps, and credential theft operations designed to surveil victims and selectively deliver malware. Individual targets included Vietnamese writer Bui Thanh Hieu and Berlin-based journalist Marina Mai, while researchers also linked the operation to compromised sites and surveillance activity across Cambodia, Laos, and the Philippines.
Security firms and platform operators said the group maintained a long-running, well-resourced infrastructure and evolved its tradecraft from phishing-heavy operations to direct intrusions against high-value targets using 0-day and N-day vulnerabilities. Observed tooling included Cobalt Strike, Mimikatz, Empire, DLL side-loading, PowerShell-based host profiling, custom loaders, and malware such as Remy RAT, with some activity linked by Facebook to CyberOne Group in Vietnam. Facebook said it removed accounts and pages, blocked associated domains, notified targeted users, and shared indicators and YARA rules with industry partners as researchers continued to document the group’s regional surveillance and lateral movement capabilities.

TTPs, infrastructure, and targeting history in one profile.
12 events from the most recent confirmed update back to the earliest known activity.
Facebook announced enforcement action against APT32 in Vietnam, removed associated accounts and Pages, blocked related domains, and notified targeted users. It linked the operation to CyberOne Group and published indicators including hashes, domains, and YARA rules.
Marina Mai learned in late 2020 that attackers had attempted to install spyware on her computer. CPJ said the targeting was linked to OceanLotus and used spear-phishing.
QiAnXin reported that from mid-2020 OceanLotus gradually moved away from spear-phishing and began directly intruding into high-value targets. The report said the group used 0-day and N-day vulnerabilities during intrusion and lateral movement.
Bui Thanh Hieu closed his blog in early 2020 because he feared for his family's safety. The closure followed sustained pressure and targeting tied to his criticism of the Vietnamese state.
FireEye published a report on APT32 and its threat to global corporations. The reference establishes a public reporting milestone on the group's cyber-espionage activity.
Volexity released research in 2017 describing a large OceanLotus digital surveillance campaign. According to CPJ, the campaign involved about 120 hacked sites, roughly 90 of them media and human rights organizations.
QiAnXin said Tianyan Lab first publicly disclosed and named OceanLotus in May 2015. This was presented as the group's first public identification.
After fleeing to Germany in 2013, Bui Thanh Hieu continued writing about Vietnamese politics on his blog Nguoi Buon Gio and on Facebook. His continued activism formed part of the context for later targeting.
QiAnXin reported that OceanLotus activity could be traced back to April 2012, marking the earliest stated start of the group's operations. The group was described as targeting victims across East Asia, Southeast Asia, and Europe.
Bui Thanh Hieu was detained in 2009 for writing critically about Vietnam's territorial disputes with China. This predates the later cyber targeting described against him.
QiAnXin published a technical analysis of OceanLotus covering its direct-intrusion methods, lateral movement scripts, host profiling, use of Empire, Mimikatz, Cobalt Strike, and Remy RAT, and its DLL-based loaders. The report also described a mining component masquerading as vmware-authd.exe.
CPJ reported that OceanLotus had targeted journalists including Marina Mai and Bui Thanh Hieu with spear-phishing and malware-laced messages. The article also highlighted prior research tying the group to compromised websites and surveillance of media and human rights organizations.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
ti.qianxin.com
Open sourcecpj.org
Open sourceabout.fb.com
Open sourcefireeye.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.