Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT32

🇻🇳APT32

🇻🇳 APT32 is a tracked threat actor in the Clankerusecase corpus. Attributed to VN. Primary motivation: State. We map 26 detection use cases to this actor across 119 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-06-11 to 2026-06-24.

crit 2
View full actor card → All threat actors MITRE ATT&CK group spec (G0050) ↗
26Use cases
2Articles
119Techniques
25IOCs

Known aliases

APT32OceanLotusSeaLotusCobalt KittyAPT-C-00Canvas CycloneBISMUTH

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1005 · Data from Local SystemT1008 · Fallback ChannelsT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1020 · Automated ExfiltrationT1021 · Remote ServicesT1021.001 · Remote Desktop ProtocolT1021.002 · SMB/Windows Admin SharesT1027.010 · Command ObfuscationT1027.011 · Fileless StorageT1027.013 · Encrypted/Encoded FileT1027.015 · CompressionT1027.016 · Junk Code InsertionT1033 · System Owner/User DiscoveryT1036.003 · Rename Legitimate UtilitiesT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.002 · Portable Executable InjectionT1056.001 · KeyloggingT1057 · Process DiscoveryT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.001 · Web ProtocolsT1071.003 · Mail ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1102 · Web ServiceT1105 · Ingress Tool TransferT1106 · Native APIT1112 · Modify RegistryT1113 · Screen CaptureT1119 · Automated CollectionT1129 · Shared ModulesT1132.001 · Standard EncodingT1135 · Network Share DiscoveryT1136.001 · Local AccountT1137 · Office Application StartupT1140 · Deobfuscate/Decode Files or InformationT1176 · Software ExtensionsT1189 · Drive-by CompromiseT1190 · Exploit Public-Facing ApplicationT1195 · Supply Chain CompromiseT1195.002 · Compromise Software Supply ChainT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1216.001 · PubPrnT1218.005 · MshtaT1218.007 · MsiexecT1218.010 · Regsvr32T1218.011 · Rundll32T1219 · Remote Access ToolsT1219.002 · Remote Desktop SoftwareT1222.002 · Linux and Mac PermissionsT1480 · Execution GuardrailsT1505.003 · Web ShellT1518.001 · Security Software DiscoveryT1528 · Steal Application Access TokenT1539 · Steal Web Session CookieT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1550.003 · Pass the TicketT1552.001 · Credentials In FilesT1552.002 · Credentials in RegistryT1553.002 · Code SigningT1555 · Credentials from Password StoresT1555.003 · Credentials from Web BrowsersT1560 · Archive Collected DataT1564.001 · Hidden Files and DirectoriesT1564.003 · Hidden WindowT1564.004 · NTFS File AttributesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1573 · Encrypted ChannelT1573.001 · Symmetric CryptographyT1574.001 · DLLT1574.002 · T1574.002T1583.001 · DomainsT1583.004 · ServerT1583.006 · Web ServicesT1585.001 · Social Media AccountsT1587.001 · MalwareT1588.001 · MalwareT1588.002 · ToolT1589 · Gather Victim Identity InformationT1589.002 · Email AddressesT1598.003 · Spearphishing LinkT1608.001 · Upload MalwareT1608.004 · Drive-by TargetT1614.001 · System Language DiscoveryT1685.005 · Clear Windows Event Logs

Detection use cases (26)

APT32/OceanLotus DLL side-loading — legitimately-signed host binary running & loading a DLL from a user-writable directory AI · profile SΣDD APT32/OceanLotus spearphishing macro chain — Office/Outlook spawning scripting engine or LOLBin AI · profile SΣDD Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Suspicious browser extension installation Internal Infostealer — non-browser process accessing browser cookie/login DBs Internal Crypto-wallet file/keystore access by non-wallet process Internal PowerShell encoded / obfuscated command Internal Trusted vendor binary / installer launching unusual children Internal Article-specific behavioural hunt — ESET takes part in Operation Endgame to disrupt Amadey and Stealc Internal SPECTRALVIPER DLL side-load: IntelAudioService.exe (renamed dtlupdate.exe) loads DtlCrashCatch.dll Bespoke OceanLotus SPECTRALVIPER C2 communication to FireAnt-campaign domains/IPs Bespoke FireAnt MetaKit trojanized setup.exe (SPECTRALVIPER downloader) by known hash Bespoke SPECTRALVIPER injected OneDrive.Sync.Service.exe beaconing (Cookie-header C2) Bespoke AI/LLM Agent Framework Runtime Spawning Shell, Recon, or Egress Child Process MITRE match AI/LLM Framework Web Service Spawns Shell or Network Tool (Agent-Framework Unauthenticated RCE) MITRE match Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match

Threat-intel articles (2)

Tracked indicators

Domains (7)

coachcybersecurity.com financemachinelearning.c gatewayrvcenter.com leadingfilipinoteams.com mxprodesign.com power-sync-services.com wbound.com

IP addresses (18)

103.119.47.104 139.162.11.152 139.180.128.42 139.99.33.239 142.91.98.77 166.88.77.186 176.111.174.140 176.124.199.207 188.114.96.1 193.156.1.16 194.26.192.191 194.68.26.241 196.251.107.130 38.60.245.37 62.60.226.159 64.188.91.237 94.154.35.25 95.85.238.4