VN

OceanLotus

High ConfidenceHigh Threat

APT32 • Canvas Cyclone • SeaLotus • APT-C-00 • BISMUTH • OCEAN BUFFALO +1 more

OceanLotus, also known as APT32 and Canvas Cyclone, is a sophisticated cyber espionage group with suspected ties to the Vietnamese government. Active since at least 2012, the group primarily targets a wide range of industries and government entities across Southeast Asia, with a particular focus on Vietnam, the Philippines, Laos, and Cambodia. Their operations have also extended to the United States and Europe. OceanLotus is known for its persistent and adaptive nature, often tailoring its tools and techniques to specific targets and security measures. The group's primary motivation is espionage, focusing on stealing proprietary business information and intellectual property. They have a history of targeting foreign corporations with interests in Vietnam's manufacturing, consumer products, and hospitality sectors, as well as automotive companies, media organizations, and human rights groups. OceanLotus employs a variety of tactics, including strategic web compromises and spear-phishing campaigns, to gain initial access to target networks. They are known for their use of both custom-developed and publicly available malware and tools, including Cobalt Strike and Mimikatz, to achieve their objectives.

Origin: Vietnam
Sponsor: State-Sponsored
Active: circa 2012 - Present
Victims: 100+ organizations
Advanced
Active
Espionage
Risk Assessment
79
Composite Risk Score
High Risk
ARCS Compliance80
Escalation Risk78
Grievance Index75
Infrastructure Impact82
History & Evolution

OceanLotus, also known as APT32 and Canvas Cyclone, is a sophisticated cyber espionage group with suspected ties to the Vietnamese government. Active since at least 2012, the group primarily targets a wide range of industries and government entities across Southeast Asia, with a particular focus on Vietnam, the Philippines, Laos, and Cambodia. Their operations have also extended to the United States and Europe. OceanLotus is known for its persistent and adaptive nature, often tailoring its tools and techniques to specific targets and security measures. The group's primary motivation is espionage, focusing on stealing proprietary business information and intellectual property. They have a history of targeting foreign corporations with interests in Vietnam's manufacturing, consumer products, and hospitality sectors, as well as automotive companies, media organizations, and human rights groups. OceanLotus employs a variety of tactics, including strategic web compromises and spear-phishing campaigns, to gain initial access to target networks. They are known for their use of both custom-developed and publicly available malware and tools, including Cobalt Strike and Mimikatz, to achieve their objectives.

Targeting

Target Sectors

GovernmentDefenseTechnologyManufacturingConsumer ProductsHospitalityAutomotiveMedia

Target Regions

Southeast AsiaUnited StatesEurope
Attribution & Affiliations

Attributed to State-Sponsored (Vietnam). Attribution confidence: High.

Intelligence Assessment
High
Threat Level
Highly
Targeting
Highly
Adaptability
High
Persistence
Continuous
Op Tempo
Active
Status

Future Outlook

OceanLotus is expected to continue operations targeting Government.

Timeline of Key Events
circa 2012
Major

First observed activity

2024
Major

Ongoing operations