Welivesecurity OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
Article Content
- •OceanLotus has shifted focus from external espionage to domestic targets in Vietnam.
- •The group deployed the SPECTRALVIPER backdoor in attacks against a construction company and stock investors.
- •Recent operations align with Vietnam's anti-corruption initiatives, indicating strategic state interests.
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a Vietnamese infrastructure and transport construction company, while the second involved a supply-chain attack on FireAnt MetaKit, a stock investment platform, affecting investors in Vietnam. The SPECTRALVIPER malware, a sophisticated 64-bit Windows backdoor, was deployed to compromise systems and gather intelligence. This shift in tactics reflects a broader trend of increased domestic monitoring amid Vietnam's anti-corruption efforts. OceanLotus, also known as APT32, has a history of targeting dissidents and foreign corporations, but its recent activities indicate a strategic pivot towards local targets. The group remains active and continues to innovate its malware arsenal, suggesting ongoing threats to Vietnamese entities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (17)
Following this threat?
Track Apt32, Backdoor.Win32.Denis and FireAnt in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Campaign Hijacks Microsoft 365 Accounts via Passkey Alerts A social engineering campaign impersonating IT support staff is actively hijacking Microsoft 365 accounts. The attackers use passkey-themed lures to trick users into providing credentials, leading to unauthorized access and data exfiltration. Microsoft Security Research has tracked these intrusions since May 2026…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…