logo

Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations « Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations | FireEye Inc

ID: 01d77418-34f9-4937-8c1f-228058f31078

STIX ID: report--01d77418-34f9-4937-8c1f-228058f31078

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2018-04-05

Last Modified Date: 2018-04-05

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye details APT32 (OceanLotus) cyber-espionage operations targeting corporations, governments, journalists, and dissidents since at least 2013–2017, describing spear-phishing ActiveMime lures that deploy multi-stage backdoors (custom and commercial like Cobalt Strike), persistence via scheduled tasks, sophisticated obfuscation, and extensive C2 infrastructure; the report includes malware capability summaries, sample IOCs (hashes, domains, IPs), a YARA rule for detection, and assessment of nation-aligned motivations and operational risk.