Clankerusecase
Threat-actor profile
← Back to main site
Home/ Threat Actors/ APT32

🇻🇳APT32

🇻🇳 APT32 is a tracked threat actor in the Clankerusecase corpus. Attributed to VN. Primary motivation: State. We map 26 detection use cases to this actor across 94 MITRE ATT&CK techniques, with 2 threat-intel articles citing them. Active in our corpus from 2026-06-11 to 2026-06-11.

crit 2
View full actor card → All threat actors MITRE ATT&CK group spec (G0050) ↗
26Use cases
2Articles
94Techniques
14IOCs

Known aliases

APT32OceanLotusSeaLotusCobalt KittyAPT-C-00Canvas CycloneBISMUTH

Top techniques

All other tracked techniques

T1003 · OS Credential DumpingT1003.001 · LSASS MemoryT1012 · Query RegistryT1016 · System Network Configuration DiscoveryT1018 · Remote System DiscoveryT1021 · Remote ServicesT1021.002 · SMB/Windows Admin SharesT1027 · Obfuscated Files or InformationT1027.010 · Command ObfuscationT1027.011 · Fileless StorageT1027.013 · Encrypted/Encoded FileT1027.016 · Junk Code InsertionT1033 · System Owner/User DiscoveryT1036 · MasqueradingT1036.003 · Rename Legitimate UtilitiesT1036.004 · Masquerade Task or ServiceT1036.005 · Match Legitimate Resource Name or LocationT1041 · Exfiltration Over C2 ChannelT1046 · Network Service DiscoveryT1047 · Windows Management InstrumentationT1048.003 · Exfiltration Over Unencrypted Non-C2 ProtocolT1049 · System Network Connections DiscoveryT1053.005 · Scheduled TaskT1055 · Process InjectionT1055.012 · Process HollowingT1056.001 · KeyloggingT1059 · Command and Scripting InterpreterT1059.001 · PowerShellT1059.003 · Windows Command ShellT1059.005 · Visual BasicT1059.007 · JavaScriptT1068 · Exploitation for Privilege EscalationT1070.004 · File DeletionT1070.006 · TimestompT1071 · Application Layer ProtocolT1071.003 · Mail ProtocolsT1071.004 · DNST1072 · Software Deployment ToolsT1078.003 · Local AccountsT1082 · System Information DiscoveryT1083 · File and Directory DiscoveryT1087.001 · Local AccountT1098.001 · Additional Cloud CredentialsT1102 · Web ServiceT1105 · Ingress Tool TransferT1112 · Modify RegistryT1135 · Network Share DiscoveryT1137 · Office Application StartupT1189 · Drive-by CompromiseT1203 · Exploitation for Client ExecutionT1204 · User ExecutionT1204.001 · Malicious LinkT1204.002 · Malicious FileT1204.004 · Malicious Copy and PasteT1216.001 · PubPrnT1218.005 · MshtaT1218.010 · Regsvr32T1218.011 · Rundll32T1219 · Remote Access ToolsT1222.002 · Linux and Mac PermissionsT1505.001 · SQL Stored ProceduresT1505.003 · Web ShellT1528 · Steal Application Access TokenT1543.003 · Windows ServiceT1547.001 · Registry Run Keys / Startup FolderT1550.002 · Pass the HashT1550.003 · Pass the TicketT1552.002 · Credentials in RegistryT1553.002 · Code SigningT1560 · Archive Collected DataT1564.001 · Hidden Files and DirectoriesT1564.003 · Hidden WindowT1564.004 · NTFS File AttributesT1566.001 · Spearphishing AttachmentT1566.002 · Spearphishing LinkT1569.002 · Service ExecutionT1570 · Lateral Tool TransferT1571 · Non-Standard PortT1573 · Encrypted ChannelT1574.001 · DLLT1574.002 · T1574.002T1583.001 · DomainsT1583.006 · Web ServicesT1585.001 · Social Media AccountsT1588.002 · ToolT1589 · Gather Victim Identity InformationT1589.002 · Email AddressesT1598.003 · Spearphishing LinkT1608.001 · Upload MalwareT1608.004 · Drive-by TargetT1685.005 · Clear Windows Event Logs

Detection use cases (26)

APT32 (OceanLotus / Cobalt Kitty) Outlook Home Page persistence via WebView URL registry key AI · profile SΣDD APT32 DLL side-loading via trusted AV/vendor binary copied to user-writable directory AI · profile SΣDD FireAnt Metakit.exe spawns unsigned setup.exe from update path (SPECTRALVIPER supply-chain delivery) Bespoke DtlCrashCatch.dll image-load by legitimate signed binary (OceanLotus DLL side-load) Bespoke OneDrive.Sync.Service.exe spawned/injected outside legitimate OneDrive chain (SPECTRALVIPER injection target) Bespoke SPECTRALVIPER C2 callout to OceanLotus FireAnt infrastructure Bespoke Public-facing MSSQL sqlservr.exe spawns suspicious child (OceanLotus transport-construction intrusion vector) Bespoke SPECTRALVIPER known-bad SHA1 observed on disk or in process Bespoke Registry Run-key persistence written by SPECTRALVIPER side-load chain Bespoke Beaconing — periodic outbound to small set of destinations Internal Network connections to article IPs / domains Internal Remote service execution — PsExec / SMB lateral movement Internal OAuth consent / suspicious app grant Internal Phishing-link click correlated to endpoint execution Internal Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) MITRE match Brand-Impersonation Domain Fetch Followed by User-Context Loader Within 10 Minutes MITRE match Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN MITRE match Cross-Platform ClickFix Paste-to-Pipe Loader (UI-Parent Shell with Decode-and-Execute Payload) MITRE match Developer package install spawning script-host with non-registry C2 within 5 minutes MITRE match Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint MITRE match Internet-Facing Service Process Spawning Unix Shell or Ingress-Tool LOLBin (Edge Zero-Day Post-Exploit) MITRE match Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution MITRE match Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain MITRE match Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition MITRE match Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress MITRE match Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes MITRE match

Threat-intel articles (2)

Tracked indicators

Domains (6)

coachcybersecurity.com financemachinelearning.c gatewayrvcenter.com leadingfilipinoteams.com mxprodesign.com power-sync-services.com

IP addresses (8)

103.119.47.104 139.162.11.152 139.180.128.42 139.99.33.239 142.91.98.77 166.88.77.186 194.68.26.241 38.60.245.37