logo

OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks

ID: 4ef69ce2-10c2-5d6a-a685-d61c75e86910

STIX ID: report--4ef69ce2-10c2-5d6a-a685-d61c75e86910

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

...
...

From mid-2024 to early 2026 Vietnam-aligned APT OceanLotus (APT32) shifted focus to domestic espionage, deploying the SPECTRALVIPER 64-bit Windows backdoor in two campaigns — a prolonged intrusion into a construction/infrastructure firm and a supply-chain compromise of the FireAnt MetaKit investment platform — using techniques such as DLL side-loading, LOLBAS abuse, renamed ProcDump, named pipes (e.g., \.\pipe\raSeCIR4gg), AES with Diffie-Hellman key exchange, and malicious update servers; the report provides indicators, timelines, affected sectors, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.