🇻🇳APT32
🇻🇳 APT32 is a tracked threat actor in the Clankerusecase corpus. Attributed to VN. Primary motivation: State. We map 26 detection use cases to this actor across 94 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-06-11 to 2026-06-11.
crit 2
26Use cases
2Articles
94Techniques
14IOCs
Known aliases
APT32OceanLotusSeaLotusCobalt KittyAPT-C-00Canvas CycloneBISMUTH
Top techniques
All other tracked techniques
T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021 · Remote ServicesT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.010 · Command ObfuscationT1027.011 · Fileless StorageT1027.013 · Encrypted/Encoded FileT1027.016 · Junk Code InsertionT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.003 · Rename Legitimate UtilitiesT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.012 · Process HollowingT1056.001 · KeyloggingT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.003 · Mail ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1098.001 · Additional Cloud CredentialsT1102 · Web ServiceT1105 · Ingress Tool TransferT1112 · Modify RegistryT1135 · Network Share DiscoveryT1137 · Office Application StartupT1189 · Drive-by CompromiseT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1216.001 · PubPrnT1218.005 · MshtaT1218.010 · Regsvr32T1218.011 · Rundll32T1219 · Remote Access ToolsT1222.002 · Linux and Mac PermissionsT1505.001 · SQL Stored ProceduresT1505.003 · Web ShellT1528 · Steal Application Access TokenT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1550.003 · Pass the TicketT1552.002 · Credentials in RegistryT1553.002 · Code SigningT1560 · Archive Collected DataT1564.001 · Hidden Files and DirectoriesT1564.003 · Hidden WindowT1564.004 · NTFS File AttributesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1573 · Encrypted ChannelT1574.001 · DLLT1574.002 · T1574.002T1583.001 · DomainsT1583.006 · Web ServicesT1585.001 · Social Media AccountsT1588.002 · ToolT1589 · Gather Victim Identity InformationT1589.002 · Email AddressesT1598.003 · Spearphishing LinkT1608.001 · Upload MalwareT1608.004 · Drive-by TargetT1685.005 · Clear Windows Event Logs
Detection use cases (26)
APT32 (OceanLotus / Cobalt Kitty) Outlook Home Page persistence via WebView URL registry key APT32 DLL side-loading via trusted AV/vendor binary copied to user-writable directory FireAnt Metakit.exe spawns unsigned setup.exe from update path (SPECTRALVIPER supply-chain delivery) DtlCrashCatch.dll image-load by legitimate signed binary (OceanLotus DLL side-load) OneDrive.Sync.Service.exe spawned/injected outside legitimate OneDrive chain (SPECTRALVIPER injection target) SPECTRALVIPER C2 callout to OceanLotus FireAnt infrastructure Public-facing MSSQL sqlservr.exe spawns suspicious child (OceanLotus transport-construction intrusion vector) SPECTRALVIPER known-bad SHA1 observed on disk or in process Registry Run-key persistence written by SPECTRALVIPER side-load chain Beaconing — periodic outbound to small set of destinations Network connections to article IPs / domains Remote service execution — PsExec / SMB lateral movement OAuth consent / suspicious app grant Phishing-link click correlated to endpoint execution Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) Developer package install spawning script-host with non-registry C2 within 5 minutes Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 MinutesThreat-intel articles (2)
Tracked indicators
Domains (6)
coachcybersecurity.com financemachinelearning.c gatewayrvcenter.com leadingfilipinoteams.com mxprodesign.com power-sync-services.comIP addresses (8)
103.119.47.104 139.162.11.152 139.180.128.42 139.99.33.239 142.91.98.77 166.88.77.186 194.68.26.241 38.60.245.37