APT32

THREAT ACTOR PROFILE

APT32

APT32

APT32

OceanLotus

APT32 is a Vietnamese state-aligned espionage group active since at least 2014. It runs long campaigns against regional governments, dissidents, journalists and private companies across Southeast Asia, and in 2024 to 2026 it shifted toward domestic targeting inside Vietnam, repeatedly deploying the SPECTRALVIPER backdoor through supply-chain compromises and DLL side-loading.

Vietnam

Government / Private sector

First seen

2014

Latest IOC

-

IP indicators

Hosts

SHA256 hashes

Posts

NAMES AND ALIASES

APT32, OceanLotus and the many vendor names

APT32 is tracked under a long list of vendor names. It maps to one entry among the espionage groups we track and profile, and its regional espionage focus overlaps with China-aligned crews like Mustang Panda.

-

-

-

GROUP PROFILE

State-aligned espionage, now turned inward

APT32 serves Vietnamese state interests through cyber espionage. It has historically pursued foreign governments, corporations with business in Vietnam, and Vietnamese dissidents and media abroad, and recent reporting shows a pivot toward domestic surveillance.

Our record places its origin as Vietnam and ties it to espionage across government and private-sector targets. ESET documented two Vietnam-focused campaigns in 2024 to 2026 that deployed the SPECTRALVIPER backdoor, including a supply-chain compromise aimed at stock investors.

The group favors spearphishing, watering-hole sites, look-alike domains and supply-chain compromise, then runs DLL side-loading chains to stay hidden. It maintains a deep custom toolset alongside heavy use of Cobalt Strike.

Facts:

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Initial Access

Russian Federation · GRU

Victims reported in our records and posts:

-

-

-

-

-

-

ATTACK LIFECYCLE

Supply chain and side-loading into SPECTRALVIPER

The stages below come from APT32 and OceanLotus activity in posts we track on our IOC Hunter feed.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

MALWARE AND TOOLING

SPECTRALVIPER, ZiChatBot and a deep custom kit

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

Initial Access

Spear-phishing remains the front door. In the 2026 campaign Hunt.io tracked as Operation Neusploit, APT28 sent convincing spear-phishing from already-compromised government accounts and abused a Microsoft Office security bypass (CVE-2026-21509) to kick off a fileless chain. A separate June 2026 cluster delivered the LameHug malware through spear-phishing ZIP archives using double-extension lures.

CVES EXPLOITED

Access through phishing and supply chain, not CVE exploitation

APT32's intrusions in our records lean on spearphishing, watering-hole sites, supply-chain compromise and DLL side-loading rather than on exploiting a consistent set of software vulnerabilities, so this profile does not list a confirmed exploited-CVE set. Detection should focus on the supply-chain-to-SPECTRALVIPER chain and the side-loading behavior.

APT32

IOCS FROM HUNT.IO PLATFORM

Latest IOCs

We currently track - IP indicators, - hosts, and - SHA256 hashes for Akira across - intelligence posts, with the most recent indicator dated -. The sample below is limited to indicators from the latest posts. It is not the full set.

APT32

Hosting Company

IPs

Date

Hosting Company

IPs

Date

144.126.202.227

LameHug exfil

06-17

Showing a sample of recent indicators

Get the complete

APT32

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT32

IOC set, full IP, host and hash history.

NOTABLE CAMPAIGNS

FireAnt supply chain and the ZiChatBot PyPI campaign

Recent reporting tracks OceanLotus' domestic pivot and new tooling.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

PixyNetLoader tracking

A clustering of roughly 90 loader samples across four sub-families from 2024 to 2026, with steganography and cloud C2, also linking to related APT28 tooling such as SlimAgent and Graphite.

Showing a sample of recent indicators

Get the complete

APT32

IOC set, full IP, host and hash history.

Showing a sample of recent indicators

Get the complete

APT32

IOC set, full IP, host and hash history.