SPECTRALVIPER is a heavily obfuscated, C++-written 64-bit Windows backdoor associated with the Vietnam-aligned OceanLotus threat actor, also known as APT32 and Canvas Cyclone. It has been used in cyberespionage operations against strategically significant Vietnamese organizations, including agribusiness, financial-services, infrastructure, transportation-construction, and stock-investment targets. The backdoor supports encrypted command-and-control over HTTPS and Windows named pipes; named-pipe communications use Diffie-Hellman key exchange and AES encryption. It can perform host reconnaissance, transfer and manipulate files and directories, load and inject PE payloads or shellcode into processes, conduct process hollowing, steal and impersonate security tokens, and adjust process privileges. SPECTRALVIPER can also support lateral movement through an orchestration model in which a C2-connected instance distributes commands to other compromised hosts via named pipes. Observed deployment chains have used DLL side-loading, process injection, and compromised software-update infrastructure. In a selective supply-chain operation targeting Vietnamese stock investors, a compromised investment-software update channel delivered a downloader that profiled hosts before selectively deploying SPECTRALVIPER. Other intrusions against Vietnamese organizations used side-loaded DLLs and likely exploitation of remote-code-execution vulnerabilities for initial access. Its control-flow flattening, dummy functions, and encrypted strings are intended to hinder static analysis and detection.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
SPECTRALVIPER is a heavily obfuscated, previously undisclosed, x64 backdoor that brings PE loading and injection, file upload and download, file and directory manipulation, and token impersonation capabilities.
30 distinct techniques documented for this family, organized by ATT&CK tactic.
MITRE ATT&CK techniques ... Execution T1059 Command and Scripting Interpreter SPECTRALVIPER was deployed using curl.
The group also targeted the construction firm, likely using remote code execution vulnerabilities, and deployed SPECTRALVIPER via DLL side-loading.
SPECTRALVIPER is heavily obfuscated using control-flow flattening and custom AES string decryption; P8LOADER also obfuscates strings.
The adversary renamed the SysInternals ProcDump utility, used for collecting memory metadata from running processes, to masquerade as the Windows debugger utility (windbg.exe).
SysInternals ProcDump was renamed to windbg.exe and abused (-md) as a LOLBAS to load an unsigned malicious DLL.
DONUTLOADER shellcode ... attempted to inject into sessionmsg.exe. SPECTRALVIPER can load and inject executable files.
SPECTRALVIPER command handlers include CreateRundll32ProcessAndHollow and CreateProcessAndHollow.
SPECTRALVIPER possesses the ability to impersonate security tokens ... Commands include StealProcessToken, ImpersonateUser, RevertToSelf, and AdjustPrivileges.
Using the renamed ProcDump application with the -md flag, the adversary loaded dbg.config, an unsigned DLL containing malicious code... One example leveraged the Internet Explorer program (ExtExport.exe) to load a DLL, while another technique involved side-loading a malicious DLL (dnsapi.dll) using a legitimate application (nslookup.exe).
Observed adversary tactics and techniques... System service discovery.
Observed adversary tactics and techniques... Remote system discovery.
SPECTRALVIPER command handler table includes GetCurrentUserName; the listed ATT&CK techniques include System owner/user discovery.
SPECTRALVIPER command handler table includes ListRunningProcesses; the listed ATT&CK techniques include Process discovery.
SPECTRALVIPER facilitates host reconnaissance, C2 communication, and lateral movement.
SPECTRALVIPER implements the Diffie-Helman key exchange protocol to exchange the key needed to encrypt and decrypt commands transmitted via the named pipe, which is AES-encrypted... cookie header... encrypted using RSA1024 asymmetric encryption and base64-encoded.
Indicators of Compromise (IOC) List Domains/URLs financemachinelearning.com leadingfilipinoteams.com coachcybersecurity.com gatewayrvcenter.com mxprodesign.com IP Address 38.60.245.37 ...
In HTTP mode, the malware will beacon to its C2 every n seconds ... The request contains a cookie header, euconsent-v2.
207 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by OceanLotus in a supply-chain-enabled campaign targeting investors and construction-related companies.
A heavily obfuscated C++ x64 Windows backdoor used in espionage intrusions. It supports PE loading and injection, token theft and impersonation, file upload/download and file-system manipulation, can run as an EXE or masquerade as a DLL, and communicates over encrypted HTTP or named-pipe C2 channels.
A backdoor used by OceanLotus/APT32 for cyberespionage, including a supply-chain attack and a long-term intrusion in Vietnam.
A backdoor used by OceanLotus in espionage campaigns. It enables host reconnaissance, command-and-control communication, and lateral movement, and was delivered via a compromised software update mechanism and DLL side-loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.