OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
ID: f134ca70-d129-5e8b-80af-4fcd48dd394c
STIX ID: report--f134ca70-d129-5e8b-80af-4fcd48dd394c
Feed Name: The Hacker News
OceanLotus conducted two related campaigns from 2024–2026 targeting domestic Vietnamese entities and stock investors: a supply-chain compromise of FireAnt Metakit that pushed the SPECTRALVIPER backdoor via an unsigned update, and a long-running intrusion into a Vietnamese transport construction company that used DLL side-loading and process injection to maintain access. ESET’s analysis details the malware’s loader behavior, C2 domains, timelines, and suggests a shift toward more selective, domestic espionage activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
