CyberSecurityBoardThreat Intel · CVEs · Products
Attack Groups

OceanLotus Targets Vietnam Investors With SPECTRALVIPER in FireAnt Supply Chain Attack

June 25, 2026

ESET has uncovered two campaigns by the Vietnam-aligned threat actor OceanLotus (APT32) targeting domestic entities and stock investors with the SPECTRALVIPER backdoor. The first campaign involved a prolonged cyber espionage operation against a Vietnamese infrastructure and transport construction corporation from mid-2024 to February 2026. The second was a supply chain attack leveraging FireAnt Metakit, a popular software platform for stock investors in Vietnam, active from October 2025 to March 2026.

The FireAnt attack exploited the software’s update mechanism, which lacked integrity validation, to distribute SPECTRALVIPER to a select group of investors. The backdoor used DLL side-loading and injected into OneDrive.Sync.Service.exe for persistence. ESET noted no further malicious updates since March 9, 2026, suggesting the campaign ended.

In the transport construction firm attack, OceanLotus likely gained initial access via remote code execution vulnerabilities in a public-facing Microsoft SQL server, deploying SPECTRALVIPER variants for lateral movement and payload delivery. The group, active since 2012, has shifted focus to domestic espionage after its front company CyberOne Group was exposed in 2020.

CVEs: CVE-2026-11645

Attack groups: OceanLotus, APT32

Malware: SPECTRALVIPER, FireAnt Metakit, SOUNDBITE, PHOREAL, WINDSHIELD, ZiChatBot

Companies: ESET, Elastic Security Labs, Kaspersky, Meta, CyberOne Group, CyberOne Security, CyberOne Technologies, Hành Tinh Company Limited

Products: Microsoft SQL Server, OneDrive.Sync.Service.exe, Python Package Index (PyPI)