惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
Vercel News
Vercel News
D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
小众软件
小众软件
美团技术团队
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
D
Docker
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
H
Hackread – Cybersecurity News, Data Breaches, AI and More
罗磊的独立博客
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
S
SegmentFault 最新的问题
云风的 BLOG
云风的 BLOG
B
Blog
雷峰网
雷峰网
The Cloudflare Blog

RSS

Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Events and conferences Canon Canada Partners with ESET to Expand Cybersecurity Services ESET releases 2026 SMB Cyber Readiness Index showing growing confidence but also concerns about AI ESET has been named the only Challenger in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection ESET Research APT Report: China-aligned groups spy in Venezuela and the Gulf, target AI robotics in S. Korea Events and conferences ESET uncovers the expanded arsenal of China-aligned Webworm; European governments targeted ESET reaffirms its global market presence with new European and Asian offices ESET supercharges AI innovation with investment to address rapidly expanding attack surface ESET joins the Agentic AI Foundation to help shape safe, human‑led agentic AI ESET’s Tony Anscombe to Co-Chair NetDiligence Cyber Risk Summit Belarus-aligned FrostyNeighbor attacks Ukrainian government, again — ESET Research discovers ESET Research uncovers CallPhantom scam on Google Play: Fake logs for real money North Korea-aligned APT group ScarCruft compromises gaming platform in supply‑chain espionage attack, ESET Research finds ESET Research discovers new China-aligned group, GopherWhisper: It abuses messaging services Discord, Slack, and Outlook to spy ESET Research: New NGate hides in NFC payment app, possibly built with AI ESET finds that SMBs currently leverage cyber insurance to arm against attacks, report incidents and improve resilience
Vietnam-aligned OceanLotus pivots to spy on domestic targ...
2026-06-11 · via RSS
  • From mid-2024 to February 2026, Vietnam-aligned APT group OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER. 
  • From October 2025 to March 2026, OceanLotus carried out a supply-chain attack leveraging FireAnt MetaKit, a software platform widely used by stock market investors in Vietnam. 
  • Domestic targets represent a shift in operational patterns for this group.
  • OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene as Vietnamese authorities have embarked upon a major crusade against corruption.

BRATISLAVA, MONTREALJune 11, 2026 — ESET Research’s tracking of OceanLotus activities from 2024–2026 has revealed a shift in operational focus as the Vietnam-aligned group adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage. ESET researchers identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock market investors in Vietnam, and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company. 

Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling. OceanLotus is known for continuously innovating and expanding its arsenal of Windows and Linux backdoors, often implementing unique network protocols or tailoring the data collection capabilities to specific operational objectives.

Between 2017 and 2020, OceanLotus attracted significant public attention following multiple reports detailing its cyberespionage activities. These included large-scale watering-hole attacks targeting Southeast Asia in 2017–2018, intrusions into corporations such as BMW and Hyundai in 2019, and the targeting of a Vietnamese dissident in Germany that same year. The group was also linked to operations against human rights defenders between 2019 and 2020, as well as espionage targeting the Wuhan municipal government in 2020. However, the group’s operations faced a setback in 2020 when Facebook publicly identified the company believed to be used as a front for OceanLotus. Following this exposure, public reporting on the group diminished significantly, and its activities received comparatively little attention for several years. 

The first campaign involved the newly discovered compromise of an infrastructure and transport construction corporation. This intrusion began in mid-2024 and persisted through January 2026. The second campaign was a supply-chain attack that began in late 2025 and continued until March 2026. In this operation, OceanLotus compromised the update server of FireAnt MetaKit, a Vietnamese stock investment platform, and replaced legitimate software updates with a malicious payload that ultimately deployed SPECTRALVIPER. This campaign appears to have targeted stock investors and may be linked to Vietnam’s recent efforts to promote securities market reforms, suggesting a possible connection to domestic monitoring or investigative objectives. 

In both cases, OceanLotus deployed its signature backdoor, SPECTRALVIPER, on victim’s systems. Notably, an operational security lapse resulted in run-time type information names being left intact in a SPECTRALVIPER sample, enabling us to reconstruct aspects of the backdoor’s internal architecture. Despite the broad potential impact of such an attack, ESET observed only a few individuals who ultimately received SPECTRALVIPER, indicating selective targeting.  

Overall, the available evidence points to a potential shift in OceanLotus’s operational patterns. Since the exposure of its physical front company in 2020, the group appears to have adopted a more selective approach to foreign espionage while placing increasing emphasis on domestic targets.

It is worth noting that OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene. In recent years, Vietnamese authorities have embarked upon a major crusade against corruption — a program baptized Blazing Furnace. Similar to Xi Jinping’s big anti-corruption push in China, this effort, launched by the Communist Party of Vietnam, is intended to demonstrate to the population that the party is willing and able to clean up its ranks to maintain its legitimacy. In this context, it seems likely that Vietnam’s security apparatus is now deploying increasingly important resources to fight corruption (and financial crime more broadly). ESET believes that OceanLotus could be somehow associated with these efforts, and that this may be another reason behind the group’s apparent refocus on domestic intelligence and surveillance.

OceanLotus, also known as APT32, is a cyberespionage group reportedly aligned with the interests of the Vietnamese government. According to ESET telemetry, activity attributed to this group dates back to 2012, and possibly earlier. OceanLotus mainly targets China and Southeast Asia (with a focus on Vietnam); it has been associated with a variety of operations, ranging from a massive digital profiling campaign to highly targeted attacks against Vietnamese human-rights activists.

For more details about OceanLotus and its latest campaign, check out the ESET Research blogpost, “OceanLotus: From external espionage to domestic targeting,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

Execution chain of the FireAnt supply-chain attack

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown—securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit www.eset.com or follow our social media, podcasts, and blogs.