OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

First seen 11 Jun 2026, 11:57 UTC Sg.Finance.YahooWelivesecurityMarkets.Businessinsidercloud.google.comwww.volexity.com+12 88% similarity 76.2

Article Content

Browse articles
ThreatCluster

From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a Vietnamese infrastructure and transport construction company, while the second involved a supply-chain attack on FireAnt MetaKit, a stock investment platform, affecting investors in Vietnam. The SPECTRALVIPER malware, a sophisticated 64-bit Windows backdoor, was deployed to compromise systems and gather intelligence. This shift in tactics reflects a broader trend of increased domestic monitoring amid Vietnam's anti-corruption efforts. OceanLotus, also known as APT32, has a history of targeting dissidents and foreign corporations, but its recent activities indicate a strategic pivot towards local targets. The group remains active and continues to innovate its malware arsenal, suggesting ongoing threats to Vietnamese entities.

Key Points: • OceanLotus has shifted focus from external espionage to domestic targets in Vietnam. • The group deployed the SPECTRALVIPER backdoor in attacks against a construction company and stock investors. • Recent operations align with Vietnam's anti-corruption initiatives, indicating strategic state interests.

ThreatCluster AI How this analysis works

Timeline

2024-06-01
OceanLotus begins targeting domestic infrastructure
The group compromised a Vietnamese infrastructure and transport construction company using SPECTRALVIPER.
ESET Research
2025-10-01
Supply-chain attack on FireAnt MetaKit
OceanLotus executed a supply-chain attack, compromising software updates to deploy SPECTRALVIPER against investors.
ESET Research
2026-01-31
SPECTRALVIPER malware identified
Elastic Security Labs reported on the SPECTRALVIPER backdoor, detailing its capabilities and methods of operation.
Elastic Security Labs
2026-06-11
ESET Research publishes findings
ESET confirms OceanLotus's strategic shift and details the two recent campaigns involving SPECTRALVIPER.
ESET Research

Community

Browse all →