From external espionage to domestic targeting

Between 2024 and 2026, our monitoring of OceanLotus activities uncovered a shift in their operational strategies. The group, believed to be aligned with the Vietnamese government, focused more on domestic espionage rather than external operations during this time frame. Specifically, OceanLotus carried out two notable campaigns using the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

It is unclear whether this shift is a temporary adjustment or a long-term strategic change for the 15-year-old APT group. However, OceanLotus continues to demonstrate aggressive tactics and a high level of sophistication in their tooling.

Key highlights from our findings include OceanLotus compromising the network of a Vietnamese infrastructure and transport construction corporation with the SPECTRALVIPER implant from mid-2024 to February 2026. Additionally, from October 2025 to March 2026, OceanLotus conducted a supply-chain attack using FireAnt Metakit to target stock investors in Vietnam. Despite the potential impact of these attacks, the group exhibited selective targeting, with only a few individuals ultimately receiving the SPECTRALVIPER backdoor.

OceanLotus, also known as APT32, has been active since at least 2012 and primarily targets China and Southeast Asia, with a focus on Vietnam. Known for its innovation and diverse arsenal of backdoors, OceanLotus has been linked to various cyberespionage activities, including attacks on human rights activists and corporations.

The group faced public scrutiny between 2017 and 2020, but resurfaced in 2023 with a new backdoor, SPECTRALVIPER. Recent activities observed from mid-2024 to early 2026 suggest a potential shift in OceanLotus’s operational focus towards domestic targets, which may be linked to Vietnam’s anti-corruption efforts.

Overall, the evidence indicates a change in OceanLotus’s operational patterns, with a move towards more selective targeting and emphasis on domestic intelligence and surveillance. This shift aligns with recent developments in Vietnam’s anti-corruption efforts and suggests a possible connection between OceanLotus’s activities and the country’s internal security priorities. This announcement indicates that Vietnamese law enforcement may have been conducting extensive investigations into the country’s stock market around the time when OceanLotus was discovered compromising the FireAnt stock trading app. It is believed that OceanLotus’s supply-chain attack was likely carried out as part of ongoing efforts to combat corruption and financial crimes in Vietnam.

The FireAnt supply-chain attack is estimated to have begun in October 2025 and lasted until March 2026. Despite identifying some stock investors exposed to the attack, only a small number of them actually received the SPECTRALVIPER backdoor. Efforts to inform FireAnt about the incident were unsuccessful.

FireAnt is a fintech company based in Vietnam that offers a platform for stock market data, analysis, and investment tools. The FireAnt MetaKit software component is designed to deliver financial market data to technical analysis platforms. The initial malicious payload was detected coming from FireAnt MetaKit’s legitimate update URL, indicating a supply-chain compromise.

The lack of signature validation in the update protocol allowed the malicious downloader to be executed as a legitimate update. The downloader collected host information and requested the next-stage payload from a staging server. A side-loading chain involving SPECTRALVIPER was then deployed, allowing for backdoor execution and communication with a C&C server.

The compromise of a Vietnamese infrastructure and transport construction corporation’s network is believed to have started in November 2024 and lasted until February 2026. Multiple SPECTRALVIPER variants were deployed across the network using shared and distinct C&C servers. The malware was injected into host processes using a side-loading mechanism.

The structure of SPECTRALVIPER as an active backdoor communicating with C&C servers over HTTPS was analyzed, providing insight into its capabilities and architectural design. The malware sends encrypted host information in HTTP Cookie headers to blend in with victim network traffic. C&C domain names are tailored for each campaign to avoid detection. For example, financemachinelearning[.]com was utilized in operations targeting stock investors, while gatewayrvcenter[.]com was identified in activity aimed at a company in the infrastructure and transport construction sector.

The SPECTRALVIPER malware supports lateral movement through an orchestration model, where a specific instance serves as an orchestrator responsible for communicating with the command and control (C&C) infrastructure. This orchestrator then sends commands to other compromised hosts through named pipe channels. The codebase indicates that XGU is an internal framework supporting SPECTRALVIPER, with the Pivot subclass handling orchestration functions. Additionally, the Feature subclass manages the malware’s remote-control capabilities.

In addition to acting as a backdoor, SPECTRALVIPER also functions as a loader, capable of injecting itself, along with other binaries or shellcode received from the C&C server, into target processes. In the analyzed campaigns, SPECTRALVIPER was configured to initially operate as a loader, injecting its backdoor component into a separate process rather than using a standalone loader. The ProcessReflector and ProcessManager classes are responsible for implementing these process manipulation and injection capabilities.

In summary, this blog post provides updates on OceanLotus, an APT group aligned with Vietnam. Recent activity indicates a shift towards domestic espionage between 2024 and 2026. Two notable incidents during this period involve a supply-chain attack targeting stock investors using FireAnt MetaKit, and the compromise of a Vietnamese infrastructure and transport construction company. In both cases, OceanLotus deployed the SPECTRALVIPER backdoor on the victim systems. An operational security oversight led to the exposure of RTTI names in a SPECTRALVIPER sample, allowing for a reconstruction of the backdoor’s internal structure.

For any inquiries regarding our research on WeLiveSecurity, please reach out to us at threatintel@eset.com. ESET Research offers private APT intelligence reports and data feeds; visit the ESET Threat Intelligence page for more information.

Indicators of Compromise (IoCs) and samples can be accessed on our GitHub repository. The MITRE ATT&CK techniques table showcases the tactics and techniques used by OceanLotus during the observed campaigns. Please rewrite the sentence for me to better understand the context.

Leave a Reply

Your email address will not be published. Required fields are marked *