OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack — Cybersecurity | Versia.media

The Vietnam-aligned threat actor known as OceanLotus has been linked to two separate operations that focused on domestic entities and stock investors, deploying a backdoor called SPECTRALVIPER.

These operations include a long-term cyber espionage campaign targeting a Vietnamese infrastructure and transport construction firm from mid-2024 through February 2026, and a supply chain attack that exploited FireAnt Metakit, a widely used software platform among stock investors in Vietnam. The second cluster of activity occurred between October 2025 and March 2026.

According to ESET, these two attack sets indicate a change in operational priorities, with the threat actor placing greater emphasis on domestic espionage rather than targeting entities abroad. The group, which has been active since 2012, has also historically targeted China.

"Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling," the Slovakian cybersecurity firm stated in a report provided to The Hacker News.

Earlier attacks orchestrated by this adversarial group have used watering holes to digitally profile website visitors, with a particular focus on hundreds of individuals and organizations linked to media, human rights, and civil society causes in 2017 and 2018. Other campaigns have specifically targeted Vietnamese human rights defenders and dissidents.

In December 2020, Meta connected OceanLotus's activities to a Vietnamese IT company called CyberOne Group, also known as CyberOne Security, CyberOne Technologies, and Hành Tinh Company Limited. Although the company denied these allegations, the public exposure led the group to remain inactive for nearly three years.

Key tools in its arsenal include SOUNDBITE (also known as Denis), PHOREAL (also known as Rizzo), WINDSHIELD (also known as Remy), and, more recently, SPECTRALVIPER, which was first documented by Elastic Security Labs in June 2023 when the threat actor resurfaced in a campaign targeting Vietnamese public companies.

As recently as last month, Kaspersky reported discovering three malicious packages on the Python Package Index (PyPI) repository designed to deliver a previously unknown malware family called ZiChatBot on Windows and Linux systems. The Russian cybersecurity company noted that the dropper used to deliver the malware shares a "64% similarity" to another dropper used by OceanLotus.

The FireAnt Metakit Supply Chain Attack

ESET's latest findings indicate that the FireAnt Metakit supply chain attack likely began around October 2, 2025, and continued until March 2026. The attack is believed to have used the software's legitimate update URL to distribute SPECTRALVIPER to a small subset of stock investors, suggesting a more targeted approach.

Despite the use of the FireAnt update server to directly distribute malicious payloads, the update configuration file located at "metakit.fireant[.]vn/Software/version.xml" lacks an integrity validation mechanism to ensure that the update binary ("setup.exe") has not been tampered with.

"Due to the absence of signature validation, Metakit.exe executed the malicious downloader as a legitimate update," ESET explained. "Once launched, the downloader performed basic host reconnaissance and transmitted the collected information via an HTTP POST request to a staging server, requesting the next-stage payload."

The payload is a DLL side-loading chain that uses a legitimate binary to launch a rogue DLL ("DtlCrashCatch.dll"), which then injects itself into the OneDrive.Sync.Service.exe process to trigger the execution of SPECTRALVIPER. The backdoor subsequently contacts a command-and-control (C2) server ("financemachinelearning[.]com") to send encrypted host information.

ESET reported that it has not observed any further malicious updates distributed through the compromised channel since March 9, 2026, suggesting that the threat actors may have concluded their campaign.

Vietnamese Transport Construction Corporation Targeted

OceanLotus has also been observed targeting an unnamed Vietnamese infrastructure and transport construction firm starting as early as November 2024, covertly maintaining access to the entity until February 2026. While the exact initial access method used by the threat actor is unclear, it is suspected to have involved exploiting remote code execution vulnerabilities in a public-facing Microsoft SQL server.

As in previous attacks, this campaign led to the deployment of the SPECTRALVIPER backdoor through DLL side-loading. Three different variants have been identified across multiple compromised hosts on the same network. The malware contacts the C2 server ("gatewayrvcenter[.]com") to transmit host-profiling data and receive instructions from the operator.

SPECTRALVIPER also enables lateral movement and acts as a loader by injecting additional binaries or shellcode retrieved from the C2 server into target processes.

"Overall, the available evidence points to a potential shift in OceanLotus's operational patterns," ESET concluded. "Since the exposure of its physical front company in 2020, the group appears to have adopted a more selective approach to foreign espionage while placing increasing emphasis on domestic targets."

← Cybersecurity