OceanLotus

☆ pin
MITRE G0040Also known as APT32, Cobalt Kitty, SeaLotus
Reports
4
First seen
Aug 28, 2024
Last seen
Jun 11, 2026
Motivation
Espionage

Targeting

Victim regions
×3
×3
Vietnam×3

Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.

Top ATT&CK techniques

T1071.001 Application Layer Protocol: Web Protocols ×3T1059.001 PowerShell ×2T1021.002 Remote Services: SMB/Windows Admin Shares ×2T1041 Exfiltration Over C2 Channel ×2T1195.002 Supply Chain Compromise: Compromise Software Supply Chain ×2T1574.002 Hijack Execution Flow: DLL Side-Loading ×2T1027 Obfuscated Files or Information ×2T1105 Ingress Tool Transfer ×2T1190 Exploit Public-Facing Application ×2T1082 System Information Discovery ×2T1055 Process Injection ×2T1566.002 Phishing – Spearphishing Link ×1

Indicators

filename ×62domain ×42hash_sha256 ×25hash_md5 ×18ip_v4 ×16url ×3registry_key ×1email ×1

Indicator values are available on Pro and via the API.

Recent reports

This page shows data on a 7-day delay. Free accounts get the full delayed feed; real-time reports, indicators, and the API start at $29/mo.