OceanLotus
MITRE G0040Also known as APT32, Cobalt Kitty, SeaLotus
Reports
4
First seen
Aug 28, 2024
Last seen
Jun 11, 2026
Motivation
Espionage
Targeting
Victim regions
×3×3
Vietnam×3
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1071.001 Application Layer Protocol: Web Protocols ×3T1059.001 PowerShell ×2T1021.002 Remote Services: SMB/Windows Admin Shares ×2T1041 Exfiltration Over C2 Channel ×2T1195.002 Supply Chain Compromise: Compromise Software Supply Chain ×2T1574.002 Hijack Execution Flow: DLL Side-Loading ×2T1027 Obfuscated Files or Information ×2T1105 Ingress Tool Transfer ×2T1190 Exploit Public-Facing Application ×2T1082 System Information Discovery ×2T1055 Process Injection ×2T1566.002 Phishing – Spearphishing Link ×1
Indicators
filename ×62domain ×42hash_sha256 ×25hash_md5 ×18ip_v4 ×16url ×3registry_key ×1email ×1
Indicator values are available on Pro and via the API.
Recent reports
High