Our tracking of OceanLotus activities from 2024–2026 reveals a shift in operational focus. During this period, the Vietnam-aligned OceanLotus adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage. We identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock investors in Vietnam and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling.

Key points of this article:

  • From mid-2024 to February 2026, OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER.
  • From October 2025 to March 2026, OceanLotus carried out a supply-chain attack leveraging FireAnt Metakit, a software platform widely used by stock investors in Vietnam.
  • Despite the broad potential impact of such an attack, only a few individuals ultimately received SPECTRALVIPER, indicating selective targeting.
  • An OPSEC mistake provides an internal view of SPECTRALVIPER’s architecture.

OceanLotus Profile

OceanLotus, also known as APT32, is a cyberespionage group allegedly aligned with the interests of the Vietnamese government. According to our telemetry, activity attributed to this group dates back to 2012, and possibly earlier. OceanLotus mainly targets China and Southeast Asia (with a focus on Vietnam); it has been associated with a variety of operations, ranging from a massive digital profiling campaign to highly targeted attacks against Vietnamese human-rights activists.

OceanLotus is known for continuously innovating and expanding its arsenals of Windows and Linux backdoors, often implementing unique network protocols or tailoring data collection capabilities to specific operational objectives. Its well-known tools include Denis (aka SOUNDBITE), which implements DNS tunneling for C&C communications; PHOREAL, which leverages the ICMP protocol for C&C communications; WINDSHIELD, which features an interesting proxy bypass mechanism; and its latest backdoor, SPECTRALVIPER, which includes orchestration capabilities.

OceanLotus: Exposure and Realignment

Between 2017 and 2020, OceanLotus attracted significant public attention following multiple reports detailing its cyberespionage activities. These included large-scale watering-hole attacks targeting Southeast Asia in 2017–2018, intrusions into corporations such as BMW and Hyundai in 2019, and the targeting of a Vietnamese dissident in Germany that same year. The group was also linked to operations against human rights defenders between 2019 and 2020, as well as espionage targeting the Wuhan municipal government in 2020.

The group’s operations faced a setback in 2020 when Facebook publicly identified the company believed to be used as a front for OceanLotus. Following this exposure, public reporting on the group diminished significantly, and its activities received comparatively little attention for several years.

OceanLotus resurfaced publicly in 2023 with a report from Elastic Security Labs that described an attack using a previously undocumented backdoor it named SPECTRALVIPER, targeting Vietnamese businesses. Building on this, our research examines the group’s more recent activity, observed from mid-2024 through early 2026. During this period, we identified two distinct campaigns that both relied on SPECTRALVIPER as their primary backdoor but had very different victim profiles.

The first campaign involved the compromise of an infrastructure and transport construction corporation. This intrusion began in mid-2024 and persisted through January 2026.

The second campaign was a supply-chain attack that began in late 2025 and continued until March 2026. In this operation, OceanLotus compromised the update server of FireAnt Metakit, a Vietnamese stock investment platform, and replaced legitimate software updates with a malicious payload that ultimately deployed SPECTRALVIPER. This campaign appears to have targeted stock investors and may be linked to Vietnam’s recent efforts to promote securities market reforms, suggesting a possible connection to domestic monitoring or investigative objectives.

In July 2025, a supply-chain attack involving the upload of malicious wheel packages to the Python Package Index (PyPI) was attributed to OceanLotus. However, our telemetry did not identify any affected victims, and we lack sufficient visibility to independently verify that attribution.

Overall, the available evidence points to a potential shift in OceanLotus’s operational patterns. Since the exposure of its physical front company in 2020, the group appears to have adopted a more selective approach to foreign espionage while placing increasing emphasis on domestic targets.

Context of These Campaigns

It is worth noting that OceanLotus’s latest activities appear to align with recent developments on Vietnam’s domestic scene.

In recent years, Vietnamese authorities have embarked on a major anti-corruption drive known as Blazing Furnace. Similar to Xi Jinping’s anti-corruption push in China, this effort, launched by the Communist Party of Vietnam, is intended to demonstrate that the party is willing and able to clean up its ranks to maintain legitimacy. Since 2016, this policy has led to several high-profile trials involving party officials and businessmen accused of bribing politicians. Two Vietnamese presidents have even been forced to resign since 2023 after being publicly associated with corruption scandals. In 2025 alone, the party reportedly sanctioned 9,600 of its members in cases related to corruption, economic crimes, and abuse of position.

In this context, it seems likely that Vietnam’s security apparatus is deploying increasing resources to combat corruption and financial crime more broadly. We believe OceanLotus could be associated with these efforts, and that this may be another reason behind the group’s apparent refocus on domestic intelligence and surveillance over the past two years. The two targets we identified in this campaign echo judicial sagas that have recently agitated Vietnam’s public arena.

In late October 2025, Vietnam’s financial regulation agency revealed that approximately 70 major national companies had been found to have misreported bond sales over the past decade — a revelation that led to a 5.5% slump in the country’s main stock index. This announcement suggests that Vietnamese law enforcement was possibly deploying wide-ranging investigative efforts against the country’s stock market at the same time OceanLotus was observed compromising the FireAnt stock trading application.

Based on these elements, we believe OceanLotus’s supply-chain attack was likely conducted as part of ongoing investigative efforts against corruption and financial crime in Vietnam.

Targeting Stock Investors

The Supply Chain

We estimate the FireAnt supply-chain attack began around October 2025 and continued until March 2026. During this period, we identified a small number of stock investors exposed to the supply-chain compromise; however, only a subset of them ultimately received the SPECTRALVIPER backdoor. Our team made multiple attempts to notify FireAnt of the incident but received no response.

FireAnt is a Vietnam-based fintech company that offers a platform for stock market data, analysis, and investment support tools for both individual and institutional investors. It is considered one of the leading digital investment platforms in Vietnam, providing real-time market data, technical analysis features, and AI-driven insights, along with a community component where investors can share information and opinions. Within this ecosystem, FireAnt MetaKit is a specialized software component focused on data delivery, designed to provide real-time and historical financial market data directly to technical analysis platforms such as AmiBroker, MetaStock, and MetaTrader.

On October 2nd, 2025, we detected the first malicious payload originating from FireAnt MetaKit’s legitimate update URL http://metakit.fireant[.]vn/Software/setup.exe. The domain resolved to the genuine IP address of the FireAnt update server, suggesting a supply-chain compromise scenario. Our analysis of this payload reveals a first-iteration downloader, indicating that this activity likely represents the early stage of the campaign, during which OceanLotus was still refining its tooling before deploying the full SPECTRALVIPER backdoor to selected targets.