VietnamWidely attributedUnknownMITRE G0050

APT32

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
2.1
Low signal strength
Mentions4
Sources1
High conf.1
Last seenMay 2026
First observed
2017-12-14
Last active
Origin
Vietnam
Aliases
6
Techniques
78
Campaigns
0
Vietnam

Attribution signals

4 mentions · 1 source
#1discoveredhigh
InfrastructureMalwareVictimology
antiy
May 2026

"Antiy discovered that the Oceanlotus organization, in cyberattacks targeting China, pre-compromised public network routers, cameras, and other IoT devices scattered across important provinces and cities in China through weak credential brute-forcing and vulnerability exploitation to serve as jump-off points, installing traffic forwarding tools, and relaying the theft and control traffic of the Torii remote control trojan through one or multiple jump-off points to the real Torii command and co..."

#2suspected ofmoderate
MalwareInfrastructure
wechat-qax-ti
May 2026

"OceanLotus group suspected of uploading malicious wheel packages on PyPI"

#3suspectedmoderate
Unspecified
securelist
May 2026

"OceanLotus suspected of using PyPI to deliver ZiChatBot malware"

#4may be linkedlow
Unspecified
securelist
May 2026

"we believe the packages may be linked to malware discussed in a Threat Intelligence report on OceanLotus"

Hedge terms observed

discoveredmay be linkedsuspectedsuspected of