ATT&CKReferencesAmnesty Intl. Ocean Lotus February 2021

Amnesty Intl. Ocean Lotus February 2021

Amnesty International. (2021, February 24). Vietnamese activists targeted by notorious hacking group. Retrieved March 1, 2021.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples12

TechniqueUsed byProcedure example
T1056.001
Keylogging
MalwareCobalt Strike

Cobalt Strike can track key presses with a keylogger module.

T1113
Screen Capture
MalwareCobalt Strike

Cobalt Strike's Beacon payload is capable of capturing screenshots.

T1204.001
Malicious Link
GroupAPT32

APT32 has lured targets to download a Cobalt Strike beacon by including a malicious link within spearphishing emails.

T1204.001
Malicious Link
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious links.

T1204.002
Malicious File
GroupAPT32

APT32 has attempted to lure users to execute a malicious dropper delivered via a spearphishing attachment.

T1204.002
Malicious File
MalwareKerrdown

Kerrdown has gained execution through victims opening malicious files.

T1566.001
Spearphishing Attachment
MalwareKerrdown

Kerrdown has been distributed through malicious e-mail attachments.

T1566.001
Spearphishing Attachment
GroupAPT32

APT32 has sent spearphishing emails with a malicious executable disguised as a document or spreadsheet.

T1566.002
Spearphishing Link
GroupAPT32

APT32 has sent spearphishing emails containing malicious links.

T1566.002
Spearphishing Link
MalwareKerrdown

Kerrdown has been distributed via e-mails containing a malicious link.

T1589
Gather Victim Identity Information
GroupAPT32

APT32 has conducted targeted surveillance against activists and bloggers.

T1589.002
Email Addresses
GroupAPT32

APT32 has collected e-mail addresses for activists and bloggers in order to target them with spyware.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.