Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations « Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations | FireEye Inc
ID: 01d77418-34f9-4937-8c1f-228058f31078
STIX ID: report--01d77418-34f9-4937-8c1f-228058f31078
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2018-04-05
Last Modified Date: 2018-04-05
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details APT32 (OceanLotus) cyber-espionage operations targeting corporations, governments, journalists, and dissidents since at least 2013–2017, describing spear-phishing ActiveMime lures that deploy multi-stage backdoors (custom and commercial like Cobalt Strike), persistence via scheduled tasks, sophisticated obfuscation, and extensive C2 infrastructure; the report includes malware capability summaries, sample IOCs (hashes, domains, IPs), a YARA rule for detection, and assessment of nation-aligned motivations and operational risk.
