Welivesecurity
OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a Vietnamese infrastructure and transport construction company, while the second involved a supply-chain attack on FireAnt MetaKit, a stock investment platform, affecting investors in Vietnam. The SPECTRALVIPER malware, a sophisticated 64-bit Windows backdoor, was deployed to compromise systems and gather intelligence. This shift in tactics reflects a broader trend of increased domestic monitoring amid Vietnam's anti-corruption efforts. OceanLotus, also known as APT32, has a history of targeting dissidents and foreign corporations, but its recent activities indicate a strategic pivot towards local targets. The group remains active and continues to innovate its malware arsenal, suggesting ongoing threats to Vietnamese entities.
Key Points: • OceanLotus has shifted focus from external espionage to domestic targets in Vietnam. • The group deployed the SPECTRALVIPER backdoor in attacks against a construction company and stock investors. • Recent operations align with Vietnam's anti-corruption initiatives, indicating strategic state interests.