OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs — Threadlinqs Intelligence
As of 2026-06-19, OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs is a high-severity apt threat attributed to APT32 (Vietnam), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 32 indicators of compromise.
Threat ID: TL-2026-0864 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT32 · Vietnam · ESPIONAGE
OceanLotus (APT32) is a Vietnamese state-aligned cyber espionage group active since at least 2014, targeting foreign governments, ASEAN entities, journalists, activists, and private corporations
OceanLotus, tracked publicly as APT32 (also SeaLotus, APT-C-00, ATK17, BISMUTH, Canvas Cyclone, Cobalt Kitty, Ocean Buffalo, TIN WOODLAWN, POND LOACH, and MITRE group G0050), is a cyber-espionage group widely assessed to operate in alignment with Vietnamese state interests. Operating since at least 2014, the group focuses on Southeast Asia — Vietnam, the Philippines, Laos, and Cambodia — and against entities whose intelligence value aligns with Hanoi's political and economic priorities.
The group's victimology spans foreign governments and ASEAN-related entities, journalists, activists, and human-rights defenders (including domestic Vietnamese dissidents), and private industry. Notable corporate espionage campaigns targeted the automotive sector (BMW, Toyota, Hyundai) from 2016-2018, while a 2020 campaign collected COVID-19 intelligence against China's Ministry of Emergency Management and the Wuhan government. More recent operations targeted Vietnam-focused stock-investment platforms and infrastructure/construction corporations.
OceanLotus is multi-platform. On Windows it relies on spearphishing attachments (ActiveMime .mht files renamed to .doc, COVID-themed RTF/Word lures), VBA macros with character-by-character ASCII obfuscation, and the KerrDown downloader leading to Cobalt Strike. Persistence and stealth lean heavily on DLL side-loading: legitimate, signed binaries (a renamed Google Update utility loading goopdate.dll; IntelAudioService.exe/dtlupdate.exe, Genuine.exe, Updater.exe, AutoCAD242.exe/Toolbox.exe) side-load the SPECTRALVIPER backdoor. SPECTRALVIPER provides token manipulation (StealToken, MakeToken, Revert2Self, Impersonate), process injection into OneDrive.Sync.Service.exe, and HTTPS C2 with encrypted host metadata carried in a zd_cs_pm Cookie header.
Across macOS and Linux the group deploys OSX_OCEANLOTUS.D (RSA/XOR-obfuscated strings, per-message AES-256 C2, Launch Agent/Daemon persistence, timestomping) and ZiChatBot, a backdoor that abuses the public Zulip chat service for bidirectional C2 — one topic exfiltrates system info while another delivers shellcode, with a heart emoji confirming execution. The group also abuses the software supply chain via malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor that side-loads terminate.dll) and, in an Oct 2025-Mar 2026 campaign, by compromising the FireAnt MetaKit legitimate update URL (metakit.fireant.vn) to deliver malware to Vietnamese stock investors.
C2 infrastructure characteristically blends bespoke domains (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com) with abuse of legitimate web services for both payload hosting and command-and-control, complicating network detection. Defenders should prioritize behavioral detection of DLL side-loading by signed-but-renamed binaries, anomalous outbound connections to Zulip/Dropbox/S3/Google Drive from non-user contexts, scheduled-task and Run-key persistence, and token-manipulation/process-injection chains.
Target sectors: government, media, human rights / civil society, automotive, financial / stock-investment, construction / infrastructure, technology, manufacturing
Target regions: Vietnam, Southeast Asia, Philippines, Laos, Cambodia, China, ASEAN
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 32 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1589, T1592, T1583, T1583, T1585, T1587, T1608, T1195, T1566, T1566