CyberSecurityBoardThreat Intel · CVEs · Products

Tag: OceanLotus

Attack Groups

OceanLotus (APT32) Threat Actor Profile

OceanLotus, also known as APT32, is a Vietnam-aligned advanced persistent threat group active since 2012. It has historically targeted foreign entities, including…

APT32 cyber espionage OceanLotus supply chain attack
June 25, 2026
Malware

SPECTRALVIPER Backdoor Analysis

SPECTRALVIPER is a backdoor used by OceanLotus, first documented by Elastic Security Labs in June 2023. It is deployed via DLL side-loading,…

backdoor DLL side-loading OceanLotus SPECTRALVIPER
June 25, 2026
Cyber Companies

CyberOne Group Vietnamese IT Company

CyberOne Group, also known as CyberOne Security and Hành Tinh Company Limited, was linked by Meta to OceanLotus activities in 2020. The…

CyberOne Group front company OceanLotus Vietnam
June 25, 2026
Cyber Products

Microsoft SQL Server Database Platform

Microsoft SQL Server was potentially exploited via remote code execution vulnerabilities as an initial access vector in OceanLotus's campaign against a Vietnamese…

Microsoft SQL Server OceanLotus remote code execution
June 25, 2026
Malware

ZiChatBot Malware Family

ZiChatBot is a previously unknown malware family discovered by Kaspersky on PyPI, delivered via malicious packages and linked to OceanLotus through dropper…

malware OceanLotus PyPI ZiChatBot
June 25, 2026
Attack Groups

APT32

[APT32](https://attack.mitre.org/groups/G0050) is a suspected Vietnam-based threat group that has been active since at least 2014. The group has targeted multiple private sector…

APT-C-00 APT32 BISMUTH Canvas Cyclone
April 17, 2024