Threat reportAPTTL-2026-0864

OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs

highACTIVE

OceanLotus (APT32) (TL-2026-0864), also tracked as OceanLotus, is a high-severity advanced persistent threat campaign, first published 2026-06-19. It is attributed to APT32 (Vietnam) with high confidence, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1003, T1005, T1008), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
33MITRE ATT&CK
Actors
1APT32
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0864

Threat ID
TL-2026-0864
Also known as
OceanLotus, APT32, SeaLotus, Cobalt Kitty, SPECTRALVIPER operations
Severity
HIGH
Status
ACTIVE
Category
APT
First published
Last reviewed
Attribution
APT32
Attribution confidence
HIGH
Nation-state nexus
Vietnam
Motivation
ESPIONAGE
Target sectors
government, media, human rights / civil society, automotive, financial / stock-investment, construction / infrastructure, technology, manufacturing
Target regions
Vietnam, Southeast Asia, Philippines, Laos, Cambodia, China, ASEAN
Detection rules
9
Indicators of compromise
32

Malware and tooling in OceanLotus (APT32)

Malware and tooling: Kerrdown - S0585, OSX_OCEANLOTUS.D - S0352, PHOREAL, Remy, SPECTRALVIPER, ZiChatBot, Cobalt Strike, Mimikatz, Zulip public chat service

How OceanLotus (APT32) works

OceanLotus (APT32) is a Vietnamese state-aligned cyber espionage group active since at least 2014, targeting foreign governments, ASEAN entities, journalists, activists, and private corporations across Southeast Asia. It pairs spearphishing, DLL side-loading, and supply-chain compromise with a broad custom malware arsenal (WINDSHIELD, KOMPROGO, SOUNDBITE, PHOREAL, KerrDown, SPECTRALVIPER, ZiChatBot, OSX_OCEANLOTUS.D) and abuses public cloud and chat services (Dropbox, S3, Google Drive, Zulip) for C2.

OceanLotus, tracked publicly as APT32 (also SeaLotus, APT-C-00, ATK17, BISMUTH, Canvas Cyclone, Cobalt Kitty, Ocean Buffalo, TIN WOODLAWN, POND LOACH, and MITRE group G0050), is a cyber-espionage group widely assessed to operate in alignment with Vietnamese state interests. Operating since at least 2014, the group focuses on Southeast Asia — Vietnam, the Philippines, Laos, and Cambodia — and against entities whose intelligence value aligns with Hanoi's political and economic priorities.

The group's victimology spans foreign governments and ASEAN-related entities, journalists, activists, and human-rights defenders (including domestic Vietnamese dissidents), and private industry. Notable corporate espionage campaigns targeted the automotive sector (BMW, Toyota, Hyundai) from 2016-2018, while a 2020 campaign collected COVID-19 intelligence against China's Ministry of Emergency Management and the Wuhan government. More recent operations targeted Vietnam-focused stock-investment platforms and infrastructure/construction corporations.

OceanLotus is multi-platform. On Windows it relies on spearphishing attachments (ActiveMime .mht files renamed to .doc, COVID-themed RTF/Word lures), VBA macros with character-by-character ASCII obfuscation, and the KerrDown downloader leading to Cobalt Strike. Persistence and stealth lean heavily on DLL side-loading: legitimate, signed binaries (a renamed Google Update utility loading goopdate.dll; IntelAudioService.exe/dtlupdate.exe, Genuine.exe, Updater.exe, AutoCAD242.exe/Toolbox.exe) side-load the SPECTRALVIPER backdoor. SPECTRALVIPER provides token manipulation (StealToken, MakeToken, Revert2Self, Impersonate), process injection into OneDrive.Sync.Service.exe, and HTTPS C2 with encrypted host metadata carried in a zd_cs_pm Cookie header.

Across macOS and Linux the group deploys OSX_OCEANLOTUS.D (RSA/XOR-obfuscated strings, per-message AES-256 C2, Launch Agent/Daemon persistence, timestomping) and ZiChatBot, a backdoor that abuses the public Zulip chat service for bidirectional C2 — one topic exfiltrates system info while another delivers shellcode, with a heart emoji confirming execution. The group also abuses the software supply chain via malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor that side-loads terminate.dll) and, in an Oct 2025-Mar 2026 campaign, by compromising the FireAnt MetaKit legitimate update URL (metakit.fireant.vn) to deliver malware to Vietnamese stock investors.

C2 infrastructure characteristically blends bespoke domains (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com) with abuse of legitimate web services for both payload hosting and command-and-control, complicating network detection. Defenders should prioritize behavioral detection of DLL side-loading by signed-but-renamed binaries, anomalous outbound connections to Zulip/Dropbox/S3/Google Drive from non-user contexts, scheduled-task and Run-key persistence, and token-manipulation/process-injection chains.

MITRE ATT&CK techniques used in TL-2026-0864

Credential Access

T1003 OS Credential Dumping

Collection

T1005 Data from Local System

Command and Control

T1008 Fallback Channels; T1071 Application Layer Protocol; T1095 Non-Application Layer Protocol; T1102 Web Service; T1573 Encrypted Channel

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1070 Indicator Removal; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution; T1574 Hijack Execution Flow

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1543 Create or Modify System Process; T1547 Boot or Logon Autostart Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Privilege Escalation

T1134 Access Token Manipulation

Initial Access

T1189 Drive-by Compromise; T1195 Supply Chain Compromise; T1566 Phishing

Lateral Movement

T1550 Use Alternate Authentication Material

Resource Development

T1583 Acquire Infrastructure; T1585 Establish Accounts; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1589 Gather Victim Identity Information; T1592 Gather Victim Host Information

Affected products and versions in OceanLotus (APT32)

  • Microsoft — Windows
    Vulnerable versions: 7; 8.1; 10; 11; Server
  • Apple — macOS
    Vulnerable versions: multiple
  • Linux — Linux (server/desktop)
    Vulnerable versions: multiple
  • Python Software Foundation — PyPI (package ecosystem)
    Vulnerable versions: uuid32-utils; colorinal; termncolor

Remediation for OceanLotus (APT32)

Immediate actions

  • Block and alert on the known OceanLotus C2 and delivery domains at the perimeter (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com, accounts.gservice[.]reviews, libjs.inquirerjs[.]com, metakit.fireant.vn)
  • Hunt for DLL side-loading by signed-but-renamed binaries (goopdate.dll alongside a renamed Google Update; SPECTRALVIPER loaders dtlupdate.exe/Genuine.exe/Updater.exe/Toolbox.exe)
  • Alert on outbound traffic to Zulip (helper.zulipchat.com), Dropbox, Amazon S3, and Google Drive from service or non-interactive process contexts

Workarounds

  • Disable Office macros from the internet by policy and block ActiveMime/.mht attachments at the mail gateway
  • Restrict execution of mshta.exe, regsvr32.exe, and rundll32.exe via WDAC/AppLocker to counter Squiblydoo and proxy execution

Longer-term hardening

  • Deploy EDR with behavioral detection for token manipulation, process injection into OneDrive.Sync.Service.exe, and scheduled-task/Run-key persistence
  • Enforce code-signing and application allow-listing to break DLL search-order hijacking
  • Implement egress filtering and DNS monitoring to detect C2 over legitimate cloud/chat services
  • Establish dependency pinning and internal package mirrors to mitigate malicious PyPI supply-chain packages

Timeline of OceanLotus (APT32)

  • OceanLotus/APT32 activity first observed; phishing campaign targeting staff of a digital rights organization.
  • Year-long intrusion against a global Asia-based corporation; automotive industrial espionage begins.
  • Large-scale watering-hole attacks across Southeast Asia; continued targeting of BMW, Toyota, and Hyundai through 2018.
  • Palo Alto Unit 42 documents the custom KerrDown downloader delivered via Word documents and RAR archives.
  • Surveillance campaigns against Vietnamese political activists and human-rights defenders begin (through 2020).
  • COVID-19 intelligence operations target China's Ministry of Emergency Management and the Wuhan government (Jan-Apr 2020).
  • OceanLotus resurfaces with the previously undocumented SPECTRALVIPER backdoor (Elastic Security Labs reporting).
  • SPECTRALVIPER operations against a Vietnamese infrastructure/transport construction corporation (through Feb 2026).
  • Supply-chain campaign abuses the legitimate FireAnt MetaKit update URL (metakit.fireant.vn) to target Vietnamese stock investors (through Mar 2026).
  • Picus Security publishes consolidated OceanLotus/APT32 tactics, malware, and TTP analysis.

Sources cited for OceanLotus (APT32)

Detection coverage for TL-2026-0864

As of 2026-06-19, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0864 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats