Threadlinqs IntelligenceStart free

Threat actorVietnamTracked since 2026-05

APT32

Also known as:APT 32APT-32APT-C-00ATK17BISMUTHCanvas CycloneCobalt KittyG0050Ocean BuffaloOcean LotusOceanLotusOceanLotus Group

As of 2026-08-28, APT32 is a Vietnam-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning campaign, apt, supply chain. Also known as APT 32, APT-32, APT-C-00, ATK17. ATT&CK coverage spans 78 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols).

Tracked threats
43 high · 1 medium
First seen
2026-05-06
Last seen
2026-07-14
ATT&CK techniques
78across 4 of 4 threats
Related CVEs
1Referenced by its activity
Attribution
VietnamNation or origin
Nation: Vietnam · 4 tracked threat(s) · Categories: CAMPAIGN, APT, SUPPLY_CHAIN, MALWARE

Activity timeline

APT32 appears in 4 tracked threats between and ; the busiest month was 2026-06 with 2 reports.

ATT&CK techniques observed

78 techniques observed across 4 of 4 tracked threats · Stealth (formerly Defense Evasion) (16), Command and Control (12), Initial Access (9), Resource Development (9), Execution (8), Persistence (8)
  • T1082 System Information Discovery — Discoveryobserved in 4 of 4 tracked threats
  • T1027 Obfuscated Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1071.001 Web Protocols — Command and Controlobserved in 3 of 4 tracked threats
  • T1140 Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion)observed in 3 of 4 tracked threats
  • T1195 Supply Chain Compromise — Initial Accessobserved in 3 of 4 tracked threats
  • T1195.002 Compromise Software Supply Chain — Initial Accessobserved in 3 of 4 tracked threats
  • T1204.002 User Execution: Malicious File — Executionobserved in 3 of 4 tracked threats
  • T1005 Data from Local System — Collectionobserved in 2 of 4 tracked threats
  • T1016 System Network Configuration Discovery — Discoveryobserved in 2 of 4 tracked threats
  • T1036 Masquerading — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1036.005 Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1041 Exfiltration Over C2 Channel — Exfiltrationobserved in 2 of 4 tracked threats
  • T1055 Process Injection — Stealth (formerly Defense Evasion)observed in 2 of 4 tracked threats
  • T1059 Command and Scripting Interpreter — Executionobserved in 2 of 4 tracked threats
  • T1071 Application Layer Protocol — Command and Controlobserved in 2 of 4 tracked threats

Tracked threats

Related CVEs

1 CVE referenced by tracked APT32 activity