APT 32, OceanLotus, SeaLotus

Description

(FireEye) Since at least 2014, FireEye has observed APT32 targeting foreign corporations with a vested interest in Vietnam’s manufacturing, consumer products, and hospitality sectors. Furthermore, there are indications that APT32 actors are targeting peripheral network security and technology infrastructure corporations.

In addition to focused targeting of the private sector with ties to Vietnam, APT32 has also targeted foreign governments, as well as Vietnamese dissidents and journalists since at least 2013.

Names

NameName-Giver
APT 32Mandiant
OceanLotusSkyEye Labs
SeaLotus?
APT-C-00Qihoo 360
Ocean BuffaloCrowdStrike
Tin WoodlawnSecureWorks
ATK 17Thales
SectorF01ThreatRecon
Pond LoachAccenture
APT-LY-100?
Lotus BaneGroup-IB

Country

State-sponsored

Motivation

  • Information theft and espionage

First Seen

2013

Observed Sectors

Observed Countries

Tools

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

b79f69a4-18a3-4d4f-b6e5-5ad3e01c984b

Last Card Change

2024-10-23