Threat group.View on attack.mitre.org
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.
| Technique | Procedure example |
|---|---|
| T1003 OS Credential Dumping |
APT32 used GetPassword_x64 to harvest credentials. |
| T1003.001 LSASS Memory |
APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials. |
| T1012 Query Registry |
APT32's backdoor can query the Windows Registry to gather system information. |
| T1016 System Network Configuration Discovery |
APT32 used the |
| T1018 Remote System Discovery |
APT32 has enumerated DC servers using the command |
| T1021.002 SMB/Windows Admin Shares |
APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution. |
| T1027.010 Command Obfuscation |
APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell. |
| T1027.011 Fileless Storage |
APT32's backdoor has stored its configuration in a registry key. |
| T1027.013 Encrypted/Encoded File |
APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| T1027.016 Junk Code Insertion |
APT32 includes garbage code to mislead anti-malware software and researchers. |
| T1033 System Owner/User Discovery |
APT32 collected the victim's username and executed the |
| T1036 Masquerading |
APT32 has disguised a Cobalt Strike beacon as a Flash Installer. |
| T1036.003 Rename Legitimate Utilities |
APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection. |
| T1036.004 Masquerade Task or Service |
APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.