Cyber Espionage is Alive and Well: APT32 and the Threat to Global Corporations
ID: 7f54baba-8ad4-4a89-83ff-bba57be80e5d
STIX ID: report--7f54baba-8ad4-4a89-83ff-bba57be80e5d
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2017-05-15
Last Modified Date: 2017-05-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
FireEye/Mandiant analyzes APT32 (OceanLotus) cyber‑espionage activity targeting private sector firms, governments, and Vietnamese diaspora since at least 2013–2017; the report details multilingual ActiveMime phishing lures, macro and scheduled‑task persistence mechanisms, multi‑stage in‑memory backdoors (including Meterpreter, Cobalt Strike BEACON, and custom backdoors), malware capabilities, extensive C2 infrastructure, and provides IOCs and detection guidance (YARA).
