Skip to content
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

First seen 11 Jun 2026, 11:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 12, 2026 at 11:08 UTC
  • OceanLotus has shifted focus from external espionage to domestic targets in Vietnam.
  • The group deployed the SPECTRALVIPER backdoor in attacks against a construction company and stock investors.
  • Recent operations align with Vietnam's anti-corruption initiatives, indicating strategic state interests.

From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a Vietnamese infrastructure and transport construction company, while the second involved a supply-chain attack on FireAnt MetaKit, a stock investment platform, affecting investors in Vietnam. The SPECTRALVIPER malware, a sophisticated 64-bit Windows backdoor, was deployed to compromise systems and gather intelligence. This shift in tactics reflects a broader trend of increased domestic monitoring amid Vietnam's anti-corruption efforts. OceanLotus, also known as APT32, has a history of targeting dissidents and foreign corporations, but its recent activities indicate a strategic pivot towards local targets. The group remains active and continues to innovate its malware arsenal, suggesting ongoing threats to Vietnamese entities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 90d ago How this analysis works

Timeline

2024-06-01
OceanLotus begins targeting domestic infrastructure
The group compromised a Vietnamese infrastructure and transport construction company using SPECTRALVIPER.
ESET Research
2025-10-01
Supply-chain attack on FireAnt MetaKit
OceanLotus executed a supply-chain attack, compromising software updates to deploy SPECTRALVIPER against investors.
ESET Research
2026-01-31
SPECTRALVIPER malware identified
Elastic Security Labs reported on the SPECTRALVIPER backdoor, detailing its capabilities and methods of operation.
Elastic Security Labs
2026-06-11
ESET Research publishes findings
ESET confirms OceanLotus's strategic shift and details the two recent campaigns involving SPECTRALVIPER.
ESET Research

More articles in this cluster (17)

Following this threat?

Track Apt32, Backdoor.Win32.Denis and FireAnt in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed