惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
Project Zero
Project Zero
O
OpenAI News
C
Cisco Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Security Latest
Security Latest
T
Tor Project blog
S
SegmentFault 最新的问题
P
Privacy & Cybersecurity Law Blog
博客园 - 【当耐特】
V
Vulnerabilities – Threatpost
W
WeLiveSecurity
小众软件
小众软件
博客园 - 聂微东
Y
Y Combinator Blog
Spread Privacy
Spread Privacy
人人都是产品经理
人人都是产品经理
Know Your Adversary
Know Your Adversary
Scott Helme
Scott Helme
B
Blog RSS Feed
N
News | PayPal Newsroom
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
TaoSecurity Blog
TaoSecurity Blog
D
Docker
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
L
LINUX DO - 最新话题
MongoDB | Blog
MongoDB | Blog
Recorded Future
Recorded Future
Webroot Blog
Webroot Blog
L
Lohrmann on Cybersecurity
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
Cloudbric
Cloudbric
罗磊的独立博客
宝玉的分享
宝玉的分享
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
News and Events Feed by Topic
GbyAI
GbyAI
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
L
LINUX DO - 热门话题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

RSS

Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Canon Canada Partners with ESET to Expand Cybersecurity Services ESET releases 2026 SMB Cyber Readiness Index showing growing confidence but also concerns about AI ESET has been named the only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea Events and conferences ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted ESET reaffirms its global market presence with new European and Asian offices ESET supercharges AI innovation with investment to address rapidly expanding attack surface ESET joins the Agentic AI Foundation to help shape safe, human‑led agentic AI ESET’s Tony Anscombe to Co-Chair NetDiligence Cyber Risk Summit Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money North Korea-aligned APT group ScarCruft compromises gaming platform in supply‑chain espionage attack, ESET Research finds ESET Research discovers new China-aligned group, GopherWhisper: It abuses messaging services Discord, Slack, and Outlook to spy ESET Research: New NGate hides in NFC payment app, possibly built with AI ESET finds that SMBs currently leverage cyber insurance to arm against attacks, report incidents and improve resilience ESET previews new AI security features to secure chatbot communications and AI workflows ESET wins four Global InfoSec Awards at RSAC 2026 ESET receives Intel vPro Certified App status – Delivering performance benefits for business customers while advancing threat detection capability ESET launches Cloud Workload Protection and AI enhancements for ESET PROTECT customers ESET presents six sessions at RSAC 2026 to advance cyber resilience ESET Research: A deep dive into EDR killers - a cornerstone of modern ransomware operations ESET sets new integration with Lumu ESET Endpoint Security for Windows v12 achieves Common Criteria certification ESET PRIVATE showcases custom security solutions at RSAC 2026 ESET launches eCrime reports ESET Research: One of Russia’s most notorious groups, Sednit, resurges with spyware in Ukraine ESET Opens 2026 Women in Cybersecurity Scholarship Applications CRN Honors ESET on Security 100 List for MDR and AI Innovations ESET’s Ryan Grant Named a 2026 CRN Channel Chief ESET Research discovers PromptSpy, the first Android threat to use generative AI ESET Named Finalist for Best Security Company in Expert Insights Awards 2026 ESET’s Tony Anscombe to Speak at NetDiligence Cyber Risk Summit Russian Sandworm group attacks energy company in Poland with DynoWiper, ESET Research discovers Fake dating app used as lure in spyware campaign targeting Pakistan, ESET Research discovers ESET is a Customers’ Choice for Endpoint Protection according to Gartner® Peer Insights™ ESET Research analyzed a critical flaw in Windows Imaging Component, which abuses JPG files ESET Wins CRN’s 2025 Gender Parity Award New Chinese group LongNosedGoblin deploys cyberespionage tools in Southeast Asia and Japan, ESET Research discovers ESET Threat Report: AI-driven attacks on the rise; NFC threats increase and evolve in sophistication Iran’s MuddyWater targets critical infrastructure in Israel and Egypt, masquerades as Snake game – ESET Research discovers ESET Research: Chinese PlushDaemon group compromises network devices for adversary-in-the-middle attacks ESET Research APT Report: Russian attacks surge in Ukraine and Europe; Chinese groups target Latin American governments ESET named a Leader in IDC MarketScape for Consumer Digital Life Protection North Korean Lazarus group targets the drone sector in Europe, likely for espionage, ESET Research discovers ESET Research discovers new spyware posing as messaging apps targeting users in the UAE ESET Enhances Free Cybersecurity Awareness Training + CSAM Resources ESET Research’s deep dive into DeceptiveDevelopment, North Korean crypto theft via fake job offers ESET Research: Russian FSB-linked Gamaredon and Turla team up to target high-profile Ukrainian entities SDSU Athletics x ESET: Proud Partnership for Student-Athlete Success ESET Research discovers UEFI-compatible HybridPetya ransomware capable of Secure Boot bypass ESET at MSP Summit 2025: Field CISO Keynote + XDR Partner Events ESET Named a Strong Performer in Independent Evaluation of MDR Services in Europe ESET Research discovers new Chinese threat group: GhostRedirector manipulates Google, poisons Windows servers with backdoors ESET discovers PromptLock, the first AI-powered ransomware" on page ESET Research: Russian RomCom group exploits new vulnerability, targets companies in Europe and Canada ESET PROTECT Elite is a Security Winner of the 2025 CRN Tech Innovators ESET has strengthened its position in the 2025 Gartner® Magic Quadrant™ for Endpoint Protection Platforms ESET Research uncovers variants of AsyncRAT, popular choice of cybercriminals Meet the 2025 Women in Cybersecurity Scholarship Winners ESET Named a 2025 Gartner® Peer Insights™ Customers’ Choice for Endpoint Protection ESET Named a Notable Provider in latest European MDR Landscape Report ESET Wins 2025 SC Award for Ransomware Remediation ESET Research discovers the first UEFI bootkit for Linux ESET Research discovers Mozilla and Windows zero day & zero click vulnerabilities exploited by Russia-aligned RomCom APT group ESET Research discovers WolfsBane, new Linux cyberespionage backdoor by China-aligned Gelsemium Days after takedown, ESET Research releases analysis of RedLine Stealer infostealer empire ESET releases latest APT report: China-aligned groups expand targeting; Iran advances diplomatic espionage ESET Research discovers new China-aligned APT group CeranaKeeper, which targeted the Thai government ESET Threat Report: Infostealers using AI & banking malware creating deepfake videos to steal money ESET Research: Ebury botnet alive & growing; 400k Linux servers compromised for cryptocurrency theft and financial gain ESET Research releases latest APT Activity Report, highlighting cyber warfare of Russia-, China-, and Iran-aligned groups ESET Research joins global operation to disrupt the Grandoreiro banking trojan operating in Latin America and Spain Iran-linked OilRig attacks Israeli organizations with cloud service-powered downloaders, ESET Research discovers ESET Research: Official Python repository served cyberespionage backdoor, gathered 10,000+ downloads Predatory SpyLoan apps — loan sharks expand their range to Android, ESET Research finds ESET Research dives into the onboarding and scamming processes of Telekopye online fraudsters ESET Research: Android malware Kamran spying via news app on residents of the disputed Kashmir region ESET Research: Infamous IoT botnet Mozi taken down via a kill switch ESET APT Activity Report: China-aligned groups campaign against EU targets; prime target of Russia-aligned groups remains Ukraine ESET Research announces comprehensive report on Latin America’s threat landscape titled ‘Looking into TUT’s tomb: The universe of threats in LATAM’ ESET Research discovers Operation Jacana, targeting governmental entity in Guyana, likely by Chinese threat group ESET Research: North Korea-linked Lazarus impersonates Meta on LinkedIn to attack an aerospace company in Spain ESET and Calgary Flames Sign Multi-Year Partnership ESET Celebrates 10 Years in Montreal ESET Business Bundles Launch on Ingram Micro Cloud Marketplace
Vietnam-aligned OceanLotus pivots to spy on domestic targets as it takes a more selective approach abroad, ESET Research finds
2026-06-11 · via RSS
  • From mid-2024 to February 2026, Vietnam-aligned APT group OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER. 
  • From October 2025 to March 2026, OceanLotus carried out a supply-chain attack leveraging FireAnt MetaKit, a software platform widely used by stock market investors in Vietnam. 
  • Domestic targets represent a shift in operational patterns for this group.
  • OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene as Vietnamese authorities have embarked upon a major crusade against corruption.

BRATISLAVA, MONTREALJune 11, 2026 — ESET Research’s tracking of OceanLotus activities from 2024–2026 has revealed a shift in operational focus as the Vietnam-aligned group adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage. ESET researchers identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock market investors in Vietnam, and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company. 

Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling. OceanLotus is known for continuously innovating and expanding its arsenal of Windows and Linux backdoors, often implementing unique network protocols or tailoring the data collection capabilities to specific operational objectives.

Between 2017 and 2020, OceanLotus attracted significant public attention following multiple reports detailing its cyberespionage activities. These included large-scale watering-hole attacks targeting Southeast Asia in 2017–2018, intrusions into corporations such as BMW and Hyundai in 2019, and the targeting of a Vietnamese dissident in Germany that same year. The group was also linked to operations against human rights defenders between 2019 and 2020, as well as espionage targeting the Wuhan municipal government in 2020. However, the group’s operations faced a setback in 2020 when Facebook publicly identified the company believed to be used as a front for OceanLotus. Following this exposure, public reporting on the group diminished significantly, and its activities received comparatively little attention for several years. 

The first campaign involved the newly discovered compromise of an infrastructure and transport construction corporation. This intrusion began in mid-2024 and persisted through January 2026. The second campaign was a supply-chain attack that began in late 2025 and continued until March 2026. In this operation, OceanLotus compromised the update server of FireAnt MetaKit, a Vietnamese stock investment platform, and replaced legitimate software updates with a malicious payload that ultimately deployed SPECTRALVIPER. This campaign appears to have targeted stock investors and may be linked to Vietnam’s recent efforts to promote securities market reforms, suggesting a possible connection to domestic monitoring or investigative objectives. 

In both cases, OceanLotus deployed its signature backdoor, SPECTRALVIPER, on victim’s systems. Notably, an operational security lapse resulted in run-time type information names being left intact in a SPECTRALVIPER sample, enabling us to reconstruct aspects of the backdoor’s internal architecture. Despite the broad potential impact of such an attack, ESET observed only a few individuals who ultimately received SPECTRALVIPER, indicating selective targeting.  

Overall, the available evidence points to a potential shift in OceanLotus’s operational patterns. Since the exposure of its physical front company in 2020, the group appears to have adopted a more selective approach to foreign espionage while placing increasing emphasis on domestic targets.

It is worth noting that OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene. In recent years, Vietnamese authorities have embarked upon a major crusade against corruption — a program baptized Blazing Furnace. Similar to Xi Jinping’s big anti-corruption push in China, this effort, launched by the Communist Party of Vietnam, is intended to demonstrate to the population that the party is willing and able to clean up its ranks to maintain its legitimacy. In this context, it seems likely that Vietnam’s security apparatus is now deploying increasingly important resources to fight corruption (and financial crime more broadly). ESET believes that OceanLotus could be somehow associated with these efforts, and that this may be another reason behind the group’s apparent refocus on domestic intelligence and surveillance.

OceanLotus, also known as APT32, is a cyberespionage group reportedly aligned with the interests of the Vietnamese government. According to ESET telemetry, activity attributed to this group dates back to 2012, and possibly earlier. OceanLotus mainly targets China and Southeast Asia (with a focus on Vietnam); it has been associated with a variety of operations, ranging from a massive digital profiling campaign to highly targeted attacks against Vietnamese human-rights activists.

For more details about OceanLotus and its latest campaign, check out the ESET Research blogpost, “OceanLotus: From external espionage to domestic targeting,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Execution chain of the FireAnt supply-chain attack

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown—securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts, and blogs.