group
APT32 G0050
- Created
- 14 December 2017
- Last modified
- 31 July 2026
- Aliases
- APT32 · SeaLotus · OceanLotus · APT-C-00 · Canvas Cyclone · BISMUTH
APT32 is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector industries as well as foreign governments, dissidents, and journalists with a strong focus on Southeast Asian countries like Vietnam, the Philippines, Laos, and Cambodia. They have extensively used strategic web compromises to compromise victims.[1][2][3]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference G0050
APT32 used Mimikatz and customized versions of Windows Credential Dumper to harvest credentials.67
APT32's backdoor can query the Windows Registry to gather system information. 8
APT32 used the ipconfig /all command to gather the IP address from the system.9
APT32 has enumerated DC servers using the command net group "Domain Controllers" /domain. The group has also used the ping command.10
APT32 used Net to use Windows' hidden network shares to copy their tools to remote machines for execution.11
Standing G0050
Reach is how much of ATT&CK this group touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 176 ATT&CK groups only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
96th percentile · 96% of 176 ATT&CK groups have this many Enterprise techniques or fewer.
94th percentile · 94% of 176 ATT&CK groups have this many tactics spanned or fewer.
88th percentile · 88% of 176 ATT&CK groups have this many tools and malware or fewer.
89% of the population shares a single value across only 4 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
58th percentile · 58% of 176 ATT&CK groups have this many detection rules per technique or fewer.
Detection coverage G0050
2366 distinct rules cover the 78 techniques recorded for this group. The 2808 technique-to-rule mappings resolve to 2366 distinct rules, because one rule can cover several techniques. 1605 Sigma · 761 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org