From mid-2024 to early 2026, the Vietnam-aligned APT group OceanLotus has intensified its focus on domestic espionage, utilizing the SPECTRALVIPER backdoor in two major campaigns. The first campaign targeted a…
A cyber espionage campaign utilizing the GoSerpent backdoor has infiltrated government networks in Southeast Asia for over five years, harvesting sensitive police and biometric data. The operation, revealed by…
Beginning in July 2025, malicious wheel packages were uploaded to the Python Package Index (PyPI) by the OceanLotus group, delivering a new malware family named ZiChatBot. This malware targets both Windows and Linux…
The OceanLotus hacker group has initiated sophisticated supply chain attacks targeting the Xinchuang IT ecosystem. This attack aims to exploit vulnerabilities within the ecosystem, impacting various organizations…