Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Groups/G0050
MITRE ATT&CK Group

APT32 (G0050)

SeaLotusOceanLotusAPT-C-00Canvas CycloneBISMUTH
ShareXLinkedInRedditHN

[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)

▪Techniques used (78)

T1550.002Pass the HashT1036MasqueradingT1059.007JavaScriptT1047Windows Management InstrumentationT1072Software Deployment ToolsT1570Lateral Tool TransferT1564.004NTFS File AttributesT1552.002Credentials in RegistryT1055Process InjectionT1216.001PubPrnT1566.001Spearphishing AttachmentT1135Network Share DiscoveryT1033System Owner/User DiscoveryT1571Non-Standard PortT1082System Information DiscoveryT1583.001DomainsT1012Query RegistryT1027.010Command ObfuscationT1059.003Windows Command ShellT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolT1574.001DLLT1566.002Spearphishing LinkT1598.003Spearphishing LinkT1087.001Local AccountT1059.001PowerShellT1003.001LSASS MemoryT1046Network Service DiscoveryT1608.004Drive-by TargetT1041Exfiltration Over C2 ChannelT1036.004Masquerade Task or ServiceT1003OS Credential DumpingT1078.003Local AccountsT1589Gather Victim Identity InformationT1070.006TimestompT1189Drive-by CompromiseT1218.011Rundll32T1059Command and Scripting InterpreterT1112Modify RegistryT1071.003Mail ProtocolsT1560Archive Collected DataT1204.001Malicious LinkT1071.001Web ProtocolsT1036.005Match Legitimate Resource Name or LocationT1070.004File DeletionT1027.011Fileless StorageT1105Ingress Tool TransferT1053.005Scheduled TaskT1036.003Rename Legitimate UtilitiesT1543.003Windows ServiceT1608.001Upload MalwareT1222.002Linux and Mac PermissionsT1569.002Service ExecutionT1018Remote System DiscoveryT1218.005MshtaT1083File and Directory DiscoveryT1685.005Clear Windows Event LogsT1059.005Visual BasicT1588.002ToolT1021.002SMB/Windows Admin SharesT1550.003Pass the TicketT1583.006Web ServicesT1505.003Web ShellT1564.001Hidden Files and DirectoriesT1016System Network Configuration DiscoveryT1027.016Junk Code InsertionT1049System Network Connections DiscoveryT1564.003Hidden WindowT1027.013Encrypted/Encoded FileT1056.001KeyloggingT1589.002Email AddressesT1218.010Regsvr32T1068Exploitation for Privilege EscalationT1585.001Social Media AccountsT1137Office Application StartupT1203Exploitation for Client ExecutionT1204.002Malicious FileT1547.001Registry Run Keys / Startup FolderT1102Web Service

▪Software used (15)

S0002MimikatztoolS0100ipconfigtoolS0585KerrdownmalwareS0154Cobalt StrikemalwareS0157SOUNDBITEmalwareS0352OSX_OCEANLOTUS.DmalwareS0156KOMPROGOmalwareS0108netshtoolS1078RotaJakiromalwareS0158PHOREALmalwareS0099ArptoolS0155WINDSHIELDmalwareS0354DenismalwareS0039NettoolS0477Goopymalware
G0050on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.