From mid-2024 to February 2026, Vietnam-aligned APT group OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER.
From October 2025 to March 2026, OceanLotus carried out a supply-chain attack leveraging FireAnt MetaKit, a software platform widely used by stock market investors in Vietnam.
Domestic targets represent a shift in operational patterns for this group.
OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene as Vietnamese authorities have embarked upon a major crusade against corruption.
BRATISLAVA, Slovakia and MONTREAL, June 11, 2026 (GLOBE NEWSWIRE) -- ESET Research’s tracking of OceanLotus activities from 2024–2026 has revealed a shift in operational focus as the Vietnam-aligned group adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage. ESET researchers identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock market investors in Vietnam, and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.
Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling. OceanLotus is known for continuously innovating and expanding its arsenal of Windows and Linux backdoors, often implementing unique network protocols or tailoring the data collection capabilities to specific operational objectives.
Between 2017 and 2020, OceanLotus attracted significant public attention following multiple reports detailing its cyberespionage activities. These included large-scale watering-hole attacks targeting Southeast Asia in 2017–2018, intrusions into corporations such as BMW and Hyundai in 2019, and the targeting of a Vietnamese dissident in Germany that same year. The group was also linked to operations against human rights defenders between 2019 and 2020, as well as espionage targeting the Wuhan municipal government in 2020. However, the group’s operations faced a setback in 2020 when publicly identified the company believed to be used as a front for OceanLotus. Following this exposure, public reporting on the group diminished significantly, and its activities received comparatively little attention for several years.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
