APT32

G0050

Threat group.View on attack.mitre.org

About this group

APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.

Techniques used78

Procedure examples78

TechniqueProcedure example
T1003
OS Credential Dumping

APT32 used GetPassword_x64 to harvest credentials.

T1003.001
LSASS Memory

APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.

T1012
Query Registry

APT32's backdoor can query the Windows Registry to gather system information.

T1016
System Network Configuration Discovery

APT32 used the ipconfig /all command to gather the IP address from the system.

T1018
Remote System Discovery

APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.

T1021.002
SMB/Windows Admin Shares

APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.

T1027.010
Command Obfuscation

APT32 has used the `Invoke-Obfuscation` framework to obfuscate their PowerShell.

T1027.011
Fileless Storage

APT32's backdoor has stored its configuration in a registry key.

T1027.013
Encrypted/Encoded File

APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor.

T1027.016
Junk Code Insertion

APT32 includes garbage code to mislead anti-malware software and researchers.

T1033
System Owner/User Discovery

APT32 collected the victim's username and executed the whoami command on the victim's machine. APT32 executed shellcode to collect the username on the victim's machine.

T1036
Masquerading

APT32 has disguised a Cobalt Strike beacon as a Flash Installer.

T1036.003
Rename Legitimate Utilities

APT32 has moved and renamed pubprn.vbs to a .txt file to avoid detection.

T1036.004
Masquerade Task or Service

APT32 has used hidden or non-printing characters to help masquerade service names, such as appending a Unicode no-break space character to a legitimate service name. APT32 has also impersonated the legitimate Flash installer file name "install_flashplayer.exe".

T1036.005
Match Legitimate Resource Name or Location

APT32 has renamed a NetCat binary to kb-10233.exe to masquerade as a Windows update. APT32 has also renamed a Cobalt Strike beacon payload to install_flashplayers.exe.

View all 78 procedure examples

Software15

Campaigns0

None recorded.

References3

  1. ESET OceanLotus Open source
    Foltýn, T. (2018, March 13). OceanLotus ships new backdoor using old tricks. Retrieved May 22, 2018.
  2. FireEye APT32 May 2017 Open source
    Carr, N.. (2017, May 14). Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations. Retrieved June 18, 2017.
  3. Volexity OceanLotus Nov 2017 Open source
    Lassalle, D., et al. (2017, November 6). OceanLotus Blossoms: Mass Digital Surveillance and Attacks Targeting ASEAN, Asian Nations, the Media, Human Rights Groups, and Civil Society. Retrieved November 6, 2017.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.