# OceanLotus (APT32) — Vietnamese State-Aligned Cyber Espionage Group: Tactics, Malware, and TTPs

> OceanLotus (APT32) is a Vietnamese state-aligned cyber espionage group active since at least 2014, targeting foreign governments, ASEAN entities, journalists, activists, and private corporations across Southeast Asia. It pairs spearphishing, DLL side-loading, and supply-chain compromise with a broad custom malware arsenal (WINDSHIELD, KOMPROGO, SOUNDBITE, PHOREAL, KerrDown, SPECTRALVIPER, ZiChatBot, OSX_OCEANLOTUS.D) and abuses public cloud and chat services (Dropbox, S3, Google Drive, Zulip) for C2.

- **Published:** 2026-06-19T00:00:00Z
- **Last reviewed:** 2026-06-19T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0864
- **ID:** TL-2026-0864
- **Severity:** HIGH
- **Category:** APT
- **Status:** ACTIVE
- **Actor:** APT32 (Vietnam)
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)

## Description

OceanLotus, tracked publicly as APT32 (also SeaLotus, APT-C-00, ATK17, BISMUTH, Canvas Cyclone, Cobalt Kitty, Ocean Buffalo, TIN WOODLAWN, POND LOACH, and MITRE group G0050), is a cyber-espionage group widely assessed to operate in alignment with Vietnamese state interests. Operating since at least 2014, the group focuses on Southeast Asia — Vietnam, the Philippines, Laos, and Cambodia — and against entities whose intelligence value aligns with Hanoi's political and economic priorities.

The group's victimology spans foreign governments and ASEAN-related entities, journalists, activists, and human-rights defenders (including domestic Vietnamese dissidents), and private industry. Notable corporate espionage campaigns targeted the automotive sector (BMW, Toyota, Hyundai) from 2016-2018, while a 2020 campaign collected COVID-19 intelligence against China's Ministry of Emergency Management and the Wuhan government. More recent operations targeted Vietnam-focused stock-investment platforms and infrastructure/construction corporations.

OceanLotus is multi-platform. On Windows it relies on spearphishing attachments (ActiveMime .mht files renamed to .doc, COVID-themed RTF/Word lures), VBA macros with character-by-character ASCII obfuscation, and the KerrDown downloader leading to Cobalt Strike. Persistence and stealth lean heavily on DLL side-loading: legitimate, signed binaries (a renamed Google Update utility loading goopdate.dll; IntelAudioService.exe/dtlupdate.exe, Genuine.exe, Updater.exe, AutoCAD242.exe/Toolbox.exe) side-load the SPECTRALVIPER backdoor. SPECTRALVIPER provides token manipulation (StealToken, MakeToken, Revert2Self, Impersonate), process injection into OneDrive.Sync.Service.exe, and HTTPS C2 with encrypted host metadata carried in a zd_cs_pm Cookie header.

Across macOS and Linux the group deploys OSX_OCEANLOTUS.D (RSA/XOR-obfuscated strings, per-message AES-256 C2, Launch Agent/Daemon persistence, timestomping) and ZiChatBot, a backdoor that abuses the public Zulip chat service for bidirectional C2 — one topic exfiltrates system info while another delivers shellcode, with a heart emoji confirming execution. The group also abuses the software supply chain via malicious PyPI wheel packages (uuid32-utils, colorinal, termncolor that side-loads terminate.dll) and, in an Oct 2025-Mar 2026 campaign, by compromising the FireAnt MetaKit legitimate update URL (metakit.fireant.vn) to deliver malware to Vietnamese stock investors.

C2 infrastructure characteristically blends bespoke domains (kmernews[.]com, financemachinelearning[.]com, gatewayrvcenter[.]com) with abuse of legitimate web services for both payload hosting and command-and-control, complicating network detection. Defenders should prioritize behavioral detection of DLL side-loading by signed-but-renamed binaries, anomalous outbound connections to Zulip/Dropbox/S3/Google Drive from non-user contexts, scheduled-task and Run-key persistence, and token-manipulation/process-injection chains.

## MITRE ATT&CK

- T1589 Gather Victim Identity Information
- T1592 Gather Victim Host Information
- T1583 Acquire Infrastructure
- T1585 Establish Accounts
- T1587 Develop Capabilities
- T1608 Stage Capabilities
- T1195 Supply Chain Compromise
- T1566 Phishing
- T1189 Drive-by Compromise
- T1059 Command and Scripting Interpreter
- T1204 User Execution
- T1053 Scheduled Task/Job
- T1543 Create or Modify System Process
- T1547 Boot or Logon Autostart Execution
- T1134 Access Token Manipulation
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1027 Obfuscated Files or Information
- T1036 Masquerading
- T1070 Indicator Removal
- T1140 Deobfuscate/Decode Files or Information
- T1218 System Binary Proxy Execution
- T1003 OS Credential Dumping
- T1082 System Information Discovery
- T1016 System Network Configuration Discovery
- T1550 Use Alternate Authentication Material
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1095 Non-Application Layer Protocol
- T1102 Web Service
- T1573 Encrypted Channel
- T1008 Fallback Channels
- T1041 Exfiltration Over C2 Channel

## Sources

- [OceanLotus (APT32) Explained: Tactics, Malware, and TTPs](https://www.picussecurity.com/resource/blog/oceanlotus-apt32-explained-tactics-malware-and-ttps)
- [APT32 (G0050) — MITRE ATT&CK Group](https://attack.mitre.org/groups/G0050/)
- [OSX_OCEANLOTUS.D (S0352) — MITRE ATT&CK Software](https://attack.mitre.org/software/S0352/)
- [OceanLotus: From external espionage to domestic targeting (ESET Research)](https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/)
- [Tracking OceanLotus' new Downloader, KerrDown (Palo Alto Unit 42)](https://gbhackers.com/oceanlotusapt-kerrdown-malware/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0864
