Cyber Resilience

Threat actor · all actors

APT32G0050 state

🇻🇳 VN

aka APT32, SeaLotus, OceanLotus, APT-C-00, Canvas Cyclone, BISMUTH, OceanLotus Group, Ocean Lotus, Cobalt Kitty, Sea Lotus, APT-32, APT 32, Ocean Buffalo, POND LOACH, TIN WOODLAWN, ATK17, G0050

Last updated: 2026-07-03

0attributed CVEs
106ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
years active

About this actor

[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.(Citation: FireEye APT32 May 2017)(Citation: Volexity OceanLotus Nov 2017)(Citation: ESET OceanLotus)

Source: MITRE ATT&CK

Activity timeline

No activity events recorded.

Profile

CVERiskCVSSEPSSPublishedProducts
No attributed CVEs.

Mitigating controls (NIST 800-53)

ControlTechniques coveredCoverage
SI-471 / 10667%
CM-666 / 10662%
CM-257 / 10654%
SI-351 / 10648%
CA-750 / 10647%
AC-645 / 10642%
CM-745 / 10642%
AC-343 / 10641%
AC-242 / 10640%
SI-737 / 10635%
AC-531 / 10629%
AC-429 / 10627%
SC-729 / 10627%
CM-528 / 10626%
IA-228 / 10626%

Co-occurring actors

None.

Similar actors