| gptkbp:instanceOf | gptkb:cybercrime 
 | 
                        
                            
                                | gptkbp:activeYearsStart | 2012 
 | 
                        
                            
                                | gptkbp:alsoKnownAs | gptkb:OceanLotus 
 | 
                        
                            
                                | gptkbp:area | gptkb:Europe gptkb:Southeast_Asia
 gptkb:United_States
 
 | 
                        
                            
                                | gptkbp:attributedTo | gptkb:ESET gptkb:FireEye
 gptkb:Volexity
 
 | 
                        
                            
                                | gptkbp:countryOfOrigin | gptkb:Vietnam 
 | 
                        
                            
                                | gptkbp:language | gptkb:Chinese English
 Vietnamese
 
 | 
                        
                            
                                | gptkbp:motive | espionage economic intelligence
 political intelligence
 intellectual property theft
 
 | 
                        
                            
                                | gptkbp:notableBattle | attacks on Southeast Asian governments COVID-19 related cyber espionage
 attacks on Chinese government targets
 attacks on automotive companies
 attacks on dissidents
 attacks on foreign governments
 attacks on media organizations
 attacks on multinational corporations
 
 | 
                        
                            
                                | gptkbp:relatedTo | gptkb:APT19 gptkb:APT-C-00
 OceanBuffalo
 
 | 
                        
                            
                                | gptkbp:status | active 
 | 
                        
                            
                                | gptkbp:suspect | gptkb:Vietnamese_government 
 | 
                        
                            
                                | gptkbp:target | gptkb:government governments
 dissidents
 foreign corporations
 
 | 
                        
                            
                                | gptkbp:technique | custom malware spear phishing
 watering hole attacks
 zero-day exploits
 
 | 
                        
                            
                                | gptkbp:usesMalware | gptkb:Cobalt_Strike gptkb:Backdoor.Win32.Denis
 gptkb:Denes
 gptkb:PhantomNet
 gptkb:WALNUT
 gptkb:WINDSHIELD
 KerrDown
 Ratsnif
 SOCKSTROUT
 
 | 
                        
                            
                                | gptkbp:bfsParent | gptkb:Operation_Winnti gptkb:Hacker
 
 | 
                        
                            
                                | gptkbp:bfsLayer | 7 
 | 
                        
                            
                                | https://www.w3.org/2000/01/rdf-schema#label | APT32 
 |