♡ Follow 0
Attack Groups
ESET has uncovered two campaigns by the Vietnam-aligned threat actor OceanLotus (APT32) targeting domestic entities and stock investors with the SPECTRALVIPER backdoor.…
APT32
backdoor
CVE-2026-11645
cyber espionage
June 25, 2026
♡ Follow 0
Malware
SPECTRALVIPER is a backdoor used by OceanLotus, first documented by Elastic Security Labs in June 2023. It is deployed via DLL side-loading,…
backdoor
DLL side-loading
OceanLotus
SPECTRALVIPER
June 25, 2026
♡ Follow 0
Cyber Products
OneDrive.Sync.Service.exe is a legitimate Windows process used by OceanLotus for process injection to execute the SPECTRALVIPER backdoor.
OneDrive.Sync.Service.exe
process injection
SPECTRALVIPER
June 25, 2026