logo

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

ID: f134ca70-d129-5e8b-80af-4fcd48dd394c

STIX ID: report--f134ca70-d129-5e8b-80af-4fcd48dd394c

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: [email protected] (The Hacker News)

...
...

OceanLotus conducted two related campaigns from 2024–2026 targeting domestic Vietnamese entities and stock investors: a supply-chain compromise of FireAnt Metakit that pushed the SPECTRALVIPER backdoor via an unsigned update, and a long-running intrusion into a Vietnamese transport construction company that used DLL side-loading and process injection to maintain access. ESET’s analysis details the malware’s loader behavior, C2 domains, timelines, and suggests a shift toward more selective, domestic espionage activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.