G0050: APT32
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.CitationFireEye APT32 May 2017CitationVolexity OceanLotus Nov 2017CitationESET OceanLotus
Security context for executives and security teams
APT32 is an ATT&CK group entry for a suspected Vietnam-based threat group active since at least 2014, associated with targeting private sector organizations, foreign governments, dissidents, and journalists, especially in Southeast Asia. For defenders, the practical issue is not just the name: the ATT&CK relationships show a mix of strategic web compromise, credential dumping, discovery, SMB-based lateral movement, command/file obfuscation, and multiple Windows, macOS, and Linux backdoors. This makes APT32 useful as a planning case for validating whether endpoint, identity, network, and web telemetry can connect early access to post-compromise movement.
Executive priority
Prioritize this entry if the organization operates in or supports Southeast Asia, works with government, media, civil society, or sensitive regional business interests, or has executives and users exposed to external web-based targeting. Leadership should ask whether incident response can quickly answer: which users browsed to suspicious compromised sites, which endpoints exposed credentials, which accounts moved over SMB/admin shares, and whether macOS/Linux assets are covered as well as Windows. The value is in resilience and evidence readiness, not assuming this group is currently targeting the organization.
Technical view
ATT&CK provides no official detection text for this group, so validation should be relationship-driven. The supplied relationships connect APT32 to Mimikatz and OS Credential Dumping including LSASS Memory, Windows discovery via registry and network utilities such as Net, Arp, ipconfig, and netsh, Remote System Discovery, SMB/Windows Admin Shares, and stealth techniques including command obfuscation, fileless storage, and encrypted/encoded files. Related malware includes several Windows backdoors, a macOS backdoor, and a Linux backdoor, so SOC coverage should be checked across endpoint platforms where those assets exist. Detection engineering should focus on behavioral chains: suspicious web-origin execution or payload delivery followed by discovery commands, credential access attempts, abnormal SMB/admin-share use, and persistence or backdoor-like process/network activity.
Likely telemetry
- Web proxy, secure web gateway, browser, and DNS logs for strategic web compromise investigation context
- Endpoint process creation and command-line telemetry for Net, Arp, ipconfig, netsh, registry queries, and obfuscated commands
- Windows security and EDR telemetry related to LSASS access, credential dumping behavior, and Mimikatz-like activity
- Authentication, account use, and lateral movement logs, especially SMB and Windows admin share access
- Registry, WMI repository, event log, and other fileless-storage-relevant endpoint evidence where collected
Detection direction
- Do not rely on the group name as a detection strategy; validate coverage for the ATT&CK techniques and software relationships supplied for APT32.
- Correlate discovery utilities and registry queries with preceding suspicious web activity, new processes, or unusual user context to reduce false positives from normal administration.
- Tune detections for LSASS access and credential dumping with attention to legitimate security tools and administrator activity that can resemble Mimikatz testing.
- Review SMB/admin-share detections against identity context: rare source-to-destination pairs, unusual accounts, off-hours access, or access following credential-related alerts are higher value than raw SMB events alone.
- Expect obfuscation and encoded/encrypted files to weaken simple signature matching; prioritize command-line normalization, behavioral analytics, and endpoint evidence preservation.
Mitigation priorities
- Start with credential protection and privileged access controls, because the relationships include OS credential dumping, LSASS Memory, Mimikatz, and SMB/admin-share lateral movement.
- Restrict and monitor administrative shares, remote administration pathways, and unnecessary SMB exposure between workstations and sensitive systems.
- Improve endpoint hardening and EDR visibility for Windows, macOS, and Linux assets where present, with special attention to command execution, registry activity, fileless storage locations, and suspicious network connections.
- Strengthen web browsing defenses and user-risk processes for populations exposed to strategic web compromise risk, including executives, regional staff, journalists, civil society contacts, and government-facing teams where applicable.
- Maintain incident response playbooks that preserve endpoint memory/process data, authentication logs, web logs, DNS, and network metadata needed to reconstruct credential theft and lateral movement.
Additional notes and limits
This take is based only on the supplied ATT&CK group description, external references, and relationship context. The strongest decision value comes from the pattern of associated behaviors: web compromise leading into discovery, credential access, SMB lateral movement, and backdoor activity across multiple endpoint operating systems. Local prioritization should be driven by geography, sector, sensitive populations, and actual telemetry coverage.
ATT&CK provides no official detection text and the group object itself lists no platforms or tactics. Platform references here come from related software and techniques, not from the group-level platform field. The supplied relationship list may not be complete for all APT32 activity, and this summary should not be read as a claim of active targeting, active exploitation, or guaranteed detection coverage.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
APT32
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.CitationFireEye APT32 May 2017CitationVolexity OceanLotus Nov 2017CitationESET OceanLotus
How security teams should use this page
Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.
All related ATT&CK context
No relationships are available in the current normalized data for this object.
Object version and sync metadata
The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.
Mirrored ATT&CK source object
The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.
Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.
