logo

OceanLotus: From external espionage to domestic targeting

ID: 82af0e28-537c-53a7-9363-06ace7a0140b

STIX ID: report--82af0e28-537c-53a7-9363-06ace7a0140b

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-12

...
...

This ESET analysis documents OceanLotus activity from mid‑2024 to early‑2026, describing two SPECTRALVIPER campaigns: a supply‑chain compromise of FireAnt MetaKit that delivered a SPECTRALVIPER downloader to select stock investors, and a prolonged intrusion of a Vietnamese infrastructure/transport construction company using side‑loading and process injection. The report details the execution chain, C2 domains and IPs, class structure recovered from RTTI, MITRE ATT&CK mappings, and a list of IoCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.