# APT32

> As of 2026-08-28, APT32 is a Vietnam-nexus threat actor tracked by Threadlinqs Intelligence across 4 threats spanning campaign, apt, supply chain. Also known as APT 32, APT-32, APT-C-00, ATK17. ATT&CK coverage spans 78 techniques across 13 tactics in 4 of 4 tracked threats. Most-observed techniques: T1082 (System Information Discovery), T1027 (Obfuscated Files or Information), T1071.001 (Web Protocols).

- **Nation:** Vietnam
- **Tracked threats:** 4
- **Categories:** CAMPAIGN, APT, SUPPLY_CHAIN, MALWARE
- **Also known as:** APT 32, APT-32, APT-C-00, ATK17, BISMUTH, Canvas Cyclone, Cobalt Kitty, G0050, Ocean Buffalo, Ocean Lotus, OceanLotus, OceanLotus Group
- **As of:** 2026-08-28

## ATT&CK techniques observed

78 techniques observed across 4 of 4 tracked threats. Tactics: Stealth (formerly Defense Evasion) (16), Command and Control (12), Initial Access (9), Resource Development (9), Execution (8), Persistence (8).

- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 4 of 4 tracked threats
- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1071.001](https://intel.threadlinqs.com/technique/T1071.001) Web Protocols — Command and Control — observed in 3 of 4 tracked threats
- [T1140](https://intel.threadlinqs.com/technique/T1140) Deobfuscate/Decode Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 4 tracked threats
- [T1195](https://intel.threadlinqs.com/technique/T1195) Supply Chain Compromise — Initial Access — observed in 3 of 4 tracked threats
- [T1195.002](https://intel.threadlinqs.com/technique/T1195.002) Compromise Software Supply Chain — Initial Access — observed in 3 of 4 tracked threats
- [T1204.002](https://intel.threadlinqs.com/technique/T1204.002) User Execution: Malicious File — Execution — observed in 3 of 4 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 4 tracked threats
- [T1016](https://intel.threadlinqs.com/technique/T1016) System Network Configuration Discovery — Discovery — observed in 2 of 4 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1036.005](https://intel.threadlinqs.com/technique/T1036.005) Match Legitimate Resource Name or Location — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 2 of 4 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Stealth (formerly Defense Evasion) — observed in 2 of 4 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 2 of 4 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 4 tracked threats

## Tracked threats

- [ASEC June 2026 APT Trend Report: Nation-State Actors Pivot to Cloud/OAuth Abuse, MaaS, and Supply-Chain Compromise](https://intel.threadlinqs.com/threat/TL-2026-1287) — MEDIUM
- [OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs](https://intel.threadlinqs.com/threat/TL-2026-0864) — HIGH
- [OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors](https://intel.threadlinqs.com/threat/TL-2026-0795) — HIGH
- [OceanLotus (APT32) PyPI Supply Chain Campaign — ZiChatBot Cross-Platform Malware via uuid32-utils, termncolor & colorinal Wheels Using Zulip REST API for C2](https://intel.threadlinqs.com/threat/TL-2026-0467) — HIGH

## Related CVEs

1 CVE referenced by tracked APT32 activity.

- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/APT32
