logo

OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack

ID: 8ceb40f1-a718-51b5-94db-84e9e724eaf9

STIX ID: report--8ceb40f1-a718-51b5-94db-84e9e724eaf9

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Mayura Kathir

...
...

OceanLotus (APT32) carried out a precision supply‑chain compromise by implanting the SPECTRALVIPER backdoor into FireAnt MetaKit and simultaneously maintained a tailored espionage intrusion against a Vietnamese infrastructure and transport construction firm between mid‑2024 and early‑2026; the report describes malicious update delivery over unencrypted channels, side‑loading of signed executables (DtlCrashCatch.dll and renamed dtlupdate/IntelAudioService.exe), DLL injection into OneDrive.Sync.Service.exe, HTTPS C2 beacons (including financemachinelearning.com) and provides multiple IOCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.