Threat reportAPTTL-2026-0864
OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs
OceanLotus (APT32) (TL-2026-0864), also tracked as OceanLotus, is a high-severity advanced persistent threat campaign, first published 2026-06-19. It is attributed to APT32 (Vietnam) with high confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1003, T1005, T1008), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 33MITRE ATT&CK
- Actors
- 1APT32
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0864
- Threat ID
- TL-2026-0864
- Also known as
- OceanLotus, APT32, SeaLotus, Cobalt Kitty, SPECTRALVIPER operations
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- Last reviewed
- Attribution
- APT32
- Attribution confidence
- HIGH
- Nation-state nexus
- Vietnam
- Motivation
- ESPIONAGE
- Target sectors
- government, media, human rights / civil society, automotive, financial / stock-investment, construction / infrastructure, technology, manufacturing
- Target regions
- Vietnam, Southeast Asia, Philippines, Laos, Cambodia, China, ASEAN
- Detection rules
- 9
- Indicators of compromise
- 32
Malware and tooling in OceanLotus (APT32)
Malware and tooling: Kerrdown - S0585, OSX_OCEANLOTUS.D - S0352, PHOREAL, Remy, SPECTRALVIPER, ZiChatBot, Cobalt Strike, Mimikatz, Zulip public chat service
How OceanLotus (APT32) works
OceanLotus (APT32) is a Vietnamese state-aligned cyber espionage group active since at least 2014, targeting foreign governments, ASEAN entities, journalists, activists, and private corporations across Southeast Asia. It pairs spearphishing, DLL side-loading, and supply-chain compromise with a broad custom malware arsenal (WINDSHIELD, KOMPROGO, SOUNDBITE, PHOREAL, KerrDown, SPECTRALVIPER, ZiChatBot, OSX_OCEANLOTUS.D) and abuses public cloud and chat services (Dropbox, S3, Google Drive, Zulip) for C2.
OceanLotus, tracked publicly as APT32 (also SeaLotus, APT-C-00, ATK17, BISMUTH, Canvas Cyclone, Cobalt Kitty, Ocean Buffalo, TIN WOODLAWN, POND LOACH, and MITRE group G0050), is a cyber-espionage group widely assessed to operate in alignment with Vietnamese state interests. Operating since at least 2014, the group focuses on Southeast Asia — Vietnam, the Philippines, Laos, and Cambodia — and against entities whose intelligence value aligns with Hanoi's political and economic priorities.
The group's victimology spans foreign governments and ASEAN-related entities, journalists, activists, and human-rights defenders (including domestic Vietnamese dissidents), and private industry. Notable corporate espionage campaigns targeted the automotive sector (BMW, Toyota, Hyundai) from 2016-2018, while a 2020 campaign collected COVID-19 intelligence against China's Ministry of Emergency Management and the Wuhan government. More recent operations targeted Vietnam-focused stock-investment platforms and infrastructure/construction corporations.
OceanLotus is multi-platform. On Windows it relies on spearphishing attachments (ActiveMime .mht files renamed to .doc, COVID-themed RTF/Word lures), VBA macros with character-by-character ASCII obfuscation, and the KerrDown downloader leading to Cobalt Strike. Persistence and stealth lean heavily on DLL side-loading: legitimate, signed binaries (a renamed Google Update utility loading goopdate.dll; IntelAudioService.exe/dtlupdate.exe, Genuine.exe, Updater.exe, AutoCAD242.exe/Toolbox.exe) side-load the SPECTRALVIPER backdoor. SPECTRALVIPER provides token manipulation (StealToken, MakeToken, Revert2Self, Impersonate), process injection into OneDrive.Sync.Service.exe, and HTTPS C2 with encrypted host metadata carried in a zd_cs_pm Cookie header.
Across macOS and Linux the group deploys OSX_OCEANLOTUS.D (RSA/XOR-obfuscated strings, per-message AES-256 C2, Launch Agent/Daemon persistence, timestomping) and ZiChatBot, a backdoor that abuses the public Zulip chat service for bidirectional C2 — one topic exfiltrates system info while another delivers shellcode, with a heart emoji confirming execution. The group also abuses the software supply chain via malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor that side-loads terminate.dll) and, in an Oct 2025-Mar 2026 campaign, by compromising the FireAnt MetaKit legitimate update URL (metakit.fireant.vn) to deliver malware to Vietnamese stock investors.
C2 infrastructure characteristically blends bespoke domains (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com) with abuse of legitimate web services for both payload hosting and command-and-control, complicating network detection. Defenders should prioritize behavioral detection of DLL side-loading by signed-but-renamed binaries, anomalous outbound connections to Zulip/Dropbox/S3/Google Drive from non-user contexts, scheduled-task and Run-key persistence, and token-manipulation/process-injection chains.
MITRE ATT&CK techniques used in TL-2026-0864
Credential Access
Collection
Command and Control
T1008 Fallback Channels; T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel
Discovery
T1016 System Network Configuration Discovery; T1082 System Information Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Privilege Escalation
T1134 Access Token Manipulation
Initial Access
T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566 Phishing
Lateral Movement
T1550 Use Alternate Authentication Material
Resource Development
T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information
Affected products and versions in OceanLotus (APT32)
Remediation for OceanLotus (APT32)
Immediate actions
- Block and alert on the known OceanLotus C2 and delivery domains at the perimeter (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com, accounts.gservice[.]reviews, libjs.inquirerjs[.]com, metakit.fireant.vn)
- Hunt for DLL side-loading by signed-but-renamed binaries (goopdate.dll alongside a renamed Google Update; SPECTRALVIPER loaders dtlupdate.exe/Genuine.exe/Updater.exe/Toolbox.exe)
- Alert on outbound traffic to Zulip (helper.zulipchat.com), Dropbox, Amazon S3, and Google Drive from service or non-interactive process contexts
Workarounds
- Disable Office macros from the internet by policy and block ActiveMime/.mht attachments at the mail gateway
- Restrict execution of mshta.exe, regsvr32.exe, and rundll32.exe via WDAC/AppLocker to counter Squiblydoo and proxy execution
Longer-term hardening
- Deploy EDR with behavioral detection for token manipulation, process injection into OneDrive.Sync.Service.exe, and scheduled-task/Run-key persistence
- Enforce code-signing and application allow-listing to break DLL search-order hijacking
- Implement egress filtering and DNS monitoring to detect C2 over legitimate cloud/chat services
- Establish dependency pinning and internal package mirrors to mitigate malicious PyPI supply-chain packages
Timeline of OceanLotus (APT32)
- OceanLotus/APT32 activity first observed; phishing campaign targeting staff of a digital rights organization.
- Year-long intrusion against a global Asia-based corporation; automotive industrial espionage begins.
- Large-scale watering-hole attacks across Southeast Asia; continued targeting of BMW, Toyota, and Hyundai through 2018.
- Palo Alto Unit 42 documents the custom KerrDown downloader delivered via Word documents and RAR archives.
- Surveillance campaigns against Vietnamese political activists and human-rights defenders begin (through 2020).
- COVID-19 intelligence operations target China's Ministry of Emergency Management and the Wuhan government (Jan-Apr 2020).
- OceanLotus resurfaces with the previously undocumented SPECTRALVIPER backdoor (Elastic Security Labs reporting).
- SPECTRALVIPER operations against a Vietnamese infrastructure/transport construction corporation (through Feb 2026).
- Supply-chain campaign abuses the legitimate FireAnt MetaKit update URL (metakit.fireant.vn) to target Vietnamese stock investors (through Mar 2026).
- Picus Security publishes consolidated OceanLotus/APT32 tactics, malware, and TTP analysis.
Sources cited for OceanLotus (APT32)
- OceanLotus (APT32) Explained: Tactics, Malware, and TTPs
- APT32 (G0050) — MITRE ATT&CK Group
- OSX_OCEANLOTUS.D (S0352) — MITRE ATT&CK Software
- OceanLotus: From external espionage to domestic targeting (ESET Research)
- Tracking OceanLotus' new Downloader, KerrDown (Palo Alto Unit 42)
- APT32 (G0050) — SeaLotus / OceanLotus / Canvas Cyclone profile
Detection coverage for TL-2026-0864
As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0864 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.