OceanLotus Shifts Focus to Domestic Espionage with SPECTRALVIPER Attacks
ID: 4ef69ce2-10c2-5d6a-a685-d61c75e86910
STIX ID: report--4ef69ce2-10c2-5d6a-a685-d61c75e86910
Feed Name: ThreatCluster
From mid-2024 to early 2026 Vietnam-aligned APT OceanLotus (APT32) shifted focus to domestic espionage, deploying the SPECTRALVIPER 64-bit Windows backdoor in two campaigns — a prolonged intrusion into a construction/infrastructure firm and a supply-chain compromise of the FireAnt MetaKit investment platform — using techniques such as DLL side-loading, LOLBAS abuse, renamed ProcDump, named pipes (e.g., \.\pipe\raSeCIR4gg), AES with Diffie-Hellman key exchange, and malicious update servers; the report provides indicators, timelines, affected sectors, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
