# OceanLotus Resurfaces With SPECTRALVIPER Backdoor: Domestic Espionage and Supply Chain Attacks Target Vietnam
Vietnam-aligned APT group OceanLotus has mounted aggressive campaigns against domestic entities and stock investors, signaling a strategic shift toward internal targets. The group leveraged a custom backdoor called SPECTRALVIPER in two distinct operations: a prolonged espionage campaign against Vietnamese infrastructure and transport entities, and a sophisticated supply chain attack on FireAnt Metakit—popular software among Vietnamese stock investors. The campaigns, documented by ESET, span from mid-2024 through March 2026, highlighting the group's continued evolution and operational sophistication after a three-year hiatus.
## The Threat: Two Coordinated Campaigns
OceanLotus orchestrated parallel attack campaigns that reveal a deliberate pivot from external targeting to domestic priorities:
Campaign 1: Long-Running Infrastructure Espionage
Campaign 2: FireAnt Metakit Supply Chain Attack
The two operations represent what security analysts describe as a "strategic rebalancing," with OceanLotus shifting from international targets—particularly entities in China, media organizations, and civil society groups—to focus on domestic Vietnamese interests.
## Background and Context: A 15-Year Threat
OceanLotus has operated continuously since 2012, establishing itself as one of Asia's most persistent and sophisticated threat actors. The group's targeting patterns have evolved significantly over the past decade:
| Period | Primary Targets | Notable Activity |
|------------|-------------------|----------------------|
| 2012-2018 | Media, civil society, international NGOs | Watering holes, spear-phishing campaigns |
| 2017-2018 | Human rights defenders, dissidents | Hundreds of individuals profiled and targeted |
| 2020s | China-based organizations | Multiple documented campaigns |
| 2024-2026 | Vietnamese domestic entities | Infrastructure, finance, investment sectors |
The CyberOne Connection and Strategic Pause
In December 2020, Meta attributed OceanLotus activities to a Vietnamese IT company called CyberOne Group (also known as CyberOne Security, CyberOne Technologies, and Hành Tinh Company Limited). The public exposure prompted the organization to retreat from public-facing operations for nearly three years. The recent resurfacing suggests either organizational restructuring or a deliberate strategy to resume operations under different operational security (OPSEC) protocols.
"Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling," according to ESET's analysis.
## Technical Details: SPECTRALVIPER and DLL Side-Loading
The SPECTRALVIPER backdoor, first documented by Elastic Security Labs in June 2023, represents OceanLotus' modern toolkit evolution. In the FireAnt Metakit compromise, the group deployed a sophisticated multi-stage attack chain that exploited the application's lack of update integrity validation:
### Attack Chain Architecture
1. Initial Compromise: Malicious payload delivered via FireAnt's update mechanism
- Legitimate update URL: metakit.fireant[.]vn/Software/version.xml
- Critical weakness: No cryptographic signature validation of the update binary ("setup.exe")
2. Execution Stage: Basic host reconnaissance
- Downloader collects system information
- Data transmitted via HTTP POST to staging server
- Requests next-stage payload from attacker infrastructure
3. Persistence Mechanism: DLL Side-Loading Chain
- Legitimate Windows binary (DtlCrashCatch.dll) exploited for code execution
- Rogue DLL injected into OneDrive.Sync.Service.exe process
- Persistent execution through legitimate Windows service
4. Command and Control: SPECTRALVIPER Activation
- Establishes encrypted communication to C2 server (financemachinelearning[.]com)
- Sends encrypted host information for operator reconnaissance
- Enables remote command execution
### Why This Approach Works
The attack exploits a fundamental security gap: FireAnt's update mechanism lacks integrity validation. Without signature verification, the application cannot distinguish between legitimate updates and malicious payloads. By compromising or intercepting the update server, attackers achieved code execution with minimal user interaction—the classic "update" action appears benign to end users.
The DLL side-loading technique is particularly effective because it leverages legitimate Windows binaries and system processes, evading traditional security controls that might flag suspicious executable launches.
## Expanding Arsenal and Supply Chain Concerns
OceanLotus' toolkit now includes multiple sophisticated malware families:
The group's recent activity extends beyond direct targeting. In May 2026, Kaspersky discovered three malicious packages on the Python Package Index (PyPI) repository designed to deliver ZiChatBot, a previously unknown malware family. The dropper's 64% similarity to OceanLotus dropper code suggests either direct attribution or copycat techniques inspired by the group's operational playbook.
## Implications for Organizations
The campaigns carry significant implications for multiple sectors:
Vietnamese Infrastructure and Finance Sectors
International Observers
Software Supply Chain Risk
## Recommendations for Defenders
Organizations should implement immediate mitigations:
Software Update Security
Threat Intelligence and Monitoring
financemachinelearning[.]com)Supply Chain Risk Management
Incident Response
OneDrive.Sync.Service.exe process injection attempts---
## HackWire Analysis
OceanLotus' resurfacing marks a significant shift in APT strategy that deserves closer examination. After a three-year hiatus following the CyberOne exposure, the group hasn't simply returned—it's returned *focused*.
The strategic pivot toward domestic Vietnamese targets suggests possible state-directed tasking. While OceanLotus has historically operated with Chinese characteristics and international scope, this new focus on Vietnam's infrastructure and financial sectors implies different priorities. The 18-month campaign against a single construction company demonstrates patience and operational maturity; the selective supply chain attack on FireAnt shows precision targeting rather than mass compromise.
What's striking is the technical conservatism combined with operational boldness. SPECTRALVIPER itself is not novel—the backdoor was documented in 2023. The DLL side-loading chain is a known technique. The exploit is remarkably simple: unsigned software updates. Yet these conventional techniques work because defenders remain distracted by zero-day mythology. The real risk in this campaign isn't some exotic vulnerability; it's that FireAnt never validated its own software before delivering it to users. That's not a sophistication gap—that's a negligence gap.
The Python Package Index discovery adds another dimension: OceanLotus is clearly testing supply chain mechanisms across multiple platforms. If they can compromise a legitimate software update server in Vietnam, why not experiment with package repositories? The ZiChatBot dropper similarity suggests either confidence in their operational security or deliberate signal-testing.
For defenders, the lesson is uncomfortable: your software supply chain is only as secure as your update mechanism. Cryptographic signature validation isn't optional. For organizations in Vietnam's critical infrastructure and finance sectors, assume you're under active espionage. Long-term dwell time means forensic analysis, threat intelligence integration, and possible reconstitution of trusted systems.
— *HackWire Editorial*
## Related Coverage