Threat Intelligence Tarot
Vol. II · 80
Vietnam (Ministry of Public Security, suspected)
G0050★★★★★
risk 3/5
✦ The Lotus Watcher ✦
APT32
OceanLotus · Canvas Cyclone · Bismuth
Private sectorAutomotiveGovernmentMediaForeign corporations in Vietnam
Active since ~2014 · Espionage, Intellectual property theft, Domestic surveillance
The Lotus blooms quietly beneath the surface of foreign enterprise, its roots threading through corporate networks before the flower is ever seen. Where trade delegations visit, the Watcher has already arrived.
Tactics & Techniques
RCN
RDV
INI
EXC
PRS
PRV
EVA
CRD
DSC
LAT
COL
C2
EXF
IMP
Notable Operations
- ◆BMW and Toyota network intrusions (2019)
- ◆Targeting of Vietnamese journalists and activists
- ◆COVID-19 research theft attempts
- ◆Southeast Asian government espionage campaigns
Defenses
- ▸User awareness training focused on document-based malware luresNIST CSF: PR.AT ↗
- ▸Macro execution blocked by default in Office suiteCIS Control 9 ↗
- ▸Registry persistence monitoring via EDRCIS Control 10 ↗
- ▸Scheduled task auditing and alertingNIST CSF: DE.CM ↗
Reversed: Their Weakness
Its reliance on spearphishing and consumer malware frameworks makes attribution straightforward. Strong endpoint detection and user awareness training collapse its primary access vectors rapidly.
Share this adversary profile
Compare →swipe to browse
Related Adversaries
Data sourced from MITRE ATT&CK. For educational purposes.