Bloomberg
A Vietnam-based hacking group is learning from China’s playbook, using increasingly sophisticated cyber-attacks to spy on competitors and help Vietnam catch up to global competitors, according to cybersecurity experts.
In the last two years, the group, which is believed to be tied to the Vietnamese government and known as APT32, has ramped up its cyber-espionage, particularly in southeast Asia, according to the cybersecurity firm CrowdStrike Inc. The hacking group’s exploits have included intellectual property theft, the firm said, the same activity for which Chinese hackers are infamous.
The automotive industry has been a key target for APT32, according to multiple experts. For example, APT32 created fake domains for Toyota Motor Corp and Hyundai Motor Co in an attempt to infiltrate the automakers’ networks, according to a researcher familiar with the matter who requested anonymity discussing companies. In March, Toyota discovered that it was targeted in Vietnam and Thailand and through a subsidiary — Toyota Tokyo Sales Holdings Inc — in Japan, according to spokesman Brian Lyons. A Toyota official, who requested anonymity discussing the hacking group, confirmed that APT32 was responsible.
Vietnam has also targeted American businesses relevant to Vietnam’s economy for years, according to experts. “What’s changed more recently, and this is consistent with broader trends in the cyberthreat actor landscape, is that they are getting better and better at it,†said Andrew Grotto, a fellow at Stanford University who served as the senior director for cybersecurity policy on the National Security Council from late 2015 to mid-2017. “They’re becoming more adept at developing their own tools, while at the same time tapping the global malware market for commercial tools.â€
The uptick in Vietnam’s economic espionage activity, which began in 2012 and has spiked since 2018 according to CrowdStrike, comes as the Trump administration seeks to curb what many believe has been rampant intellectual property theft by China — former National Security Agency Director Keith Alexander.
Competitive Edge
The Vietnamese hackers have emulated some of China’s cyber methods, albeit on a significantly smaller scale, the experts said. Vietnamese government hackers have likely “seen how successful the Chinese have been at building cyber-espionage capabilities and cybersurveillance capabilities†according to Eric Rosenbach, co-director of the Belfer Center for Science and International Affairs at the Harvard Kennedy School and a former assistant secretary of defense for global security under Obama.