SPECTRALVIPER is a heavily obfuscated 64-bit Windows backdoor associated with the Vietnam-aligned threat actor OceanLotus, also known as APT32 and Canvas Cyclone. It has been used in cyberespionage operations against strategically important Vietnamese targets, including infrastructure, transportation, agribusiness, financial-services organizations, and selected stock investors. Reporting from 2024 to 2026 indicates its use both in long-term intrusions and in a selective supply-chain compromise affecting investment software users in Vietnam.
The malware is designed for post-compromise control and operator flexibility. It supports host reconnaissance, encrypted command-and-control communications, file upload and download, file and directory manipulation, PE loading, and injection of additional binaries or shellcode into target processes. It also supports token theft and impersonation to facilitate privilege escalation and access to protected resources. Some observed tradecraft indicates an orchestration model in which one infected host relays commands to other compromised systems, enabling lateral movement through named-pipe-based interprocess or inter-host coordination.
SPECTRALVIPER has been observed delivered through DLL side-loading and process injection chains, including execution inside trusted Windows processes. In some campaigns it was staged by companion components such as P8LOADER, POWERSEAL, and DONUTLOADER. Related tooling has included in-memory evasion of AMSI and ETW, use of masquerading, and abuse of legitimate signed binaries to load malicious code. The malware can run as an executable or masquerade as a DLL exporting legitimate-looking function names.
Its command-and-control traffic has been observed over HTTP and HTTPS with encrypted host profiling data embedded in cookie fields, and it also supports a named-pipe communication channel protected with cryptographic key exchange and symmetric encryption. The family is notable for strong obfuscation, frequent recompilation, and stealth-oriented deployment conventions, making behavioral and memory-based detection more effective than static signatures.
Operational use of SPECTRALVIPER has been linked with moderate confidence to OceanLotus activity that appears increasingly focused on domestic Vietnamese espionage. Documented campaigns include a supply-chain attack abusing a financial software update mechanism to selectively target stock investors, as well as prolonged intrusions into Vietnamese infrastructure and transport organizations. These operations reflect a mature espionage capability emphasizing stealth, selective victimization, and sustained access within high-value environments.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
OceanLotus targeted Vietnamese stock investors and infrastructure and transportation construction companies by exploiting the FireAnt MetaKit supply chain breach and utilizing SPECTRALVIPER.
24 distinct techniques documented for this family, organized by ATT&CK tactic.
Although the initial access vector was not directly observed, our analysis of victim's public-facing servers suggests that the attacker may have exploited remote code execution (RCE) vulnerabilities in a Microsoft SQL server to establish an initial foothold.
MITRE ATT&CK techniques ... Execution T1059 Command and Scripting Interpreter SPECTRALVIPER was deployed using curl.
The group also targeted the construction firm, likely using remote code execution vulnerabilities, and deployed SPECTRALVIPER via DLL side-loading.
Anti-analysis throughout: every family is heavily obfuscated with control-flow flattening and multi-level dummy functions, and AES-encrypted strings.
MITRE ATT&CK techniques ... Defense Evasion T1036 Masquerading Side-loading hosts were renamed.
SysInternals ProcDump was renamed to windbg.exe and abused (-md) as a LOLBAS to load an unsigned malicious DLL.
MITRE ATT&CK techniques ... Lateral Movement T1021 Remote Services The SPECTRALVIPER orchestrator can distribute commands to other instances.
The backdoor was dropped over SMB from an already-compromised endpoint.
SPECTRALVIPER also supports lateral movement through an orchestration model, in which one instance is designated as an orchestrator responsible for communicating with the C&C infrastructure. This orchestrator distributes commands to other compromised hosts via named pipe channels.
Indicators of Compromise (IOC) List Domains/URLs financemachinelearning.com leadingfilipinoteams.com coachcybersecurity.com gatewayrvcenter.com mxprodesign.com IP Address 38.60.245.37 ...
SPECTRALVIPER communicates over HTTP — beaconing at a random 10-99 second interval, protecting data with RSA-1024 plus AES and hiding it in a ‘euconsent-v2’ cookie.
MITRE ATT&CK techniques ... Command and Control T1105 Ingress Tool Transfer A fake update downloaded and executed SPECTRALVIPER.
202 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware used by OceanLotus in a supply-chain-enabled campaign targeting investors and construction-related companies.
A heavily obfuscated C++ x64 Windows backdoor used in espionage intrusions. It supports PE loading and injection, token theft and impersonation, file upload/download and file-system manipulation, can run as an EXE or masquerade as a DLL, and communicates over encrypted HTTP or named-pipe C2 channels.
A backdoor used by OceanLotus/APT32 for cyberespionage, including a supply-chain attack and a long-term intrusion in Vietnam.
A backdoor used by OceanLotus in espionage campaigns. It enables host reconnaissance, command-and-control communication, and lateral movement, and was delivered via a compromised software update mechanism and DLL side-loading.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.