ESET attributed a targeted supply-chain attack to OceanLotus (APT32), saying the Vietnam-aligned espionage group compromised the update server for FireAnt MetaKit, a software component used by Vietnamese stock investors, and pushed malicious updates between October 2025 and March 2026. The tampered updates delivered a downloader that used DLL side-loading to install the SPECTRALVIPER backdoor, with researchers saying the operation was selective rather than a broad mass infection campaign. FireAnt MetaKit’s update process reportedly lacked integrity checks and TLS protection, allowing attackers to replace legitimate packages and abuse the trusted update channel.
Researchers said the malware used HTTPS for command-and-control, injected into OneDrive.Sync.Service.exe, and relied on infrastructure including financemachinelearning[.]com, while a parallel OceanLotus intrusion hit an unnamed Vietnamese infrastructure and transport construction company after suspected exploitation of remote code execution flaws in a public-facing Microsoft SQL Server. Multiple SPECTRALVIPER variants were then used for persistence, profiling, and lateral movement. The campaigns indicate a sharper OceanLotus focus on domestic Vietnamese surveillance, including targets tied to finance, infrastructure, and potentially politically sensitive anti-corruption and market investigations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The FireAnt MetaKit compromise continued until March 2026, selectively delivering malware to Vietnamese stock investors. ESET said the attack chain relied on missing update integrity validation, and one report also noted the absence of TLS protection in the update mechanism.
The campaign against the unnamed Vietnamese infrastructure and transport construction corporation remained active until February 2026. During the intrusion, multiple SPECTRALVIPER variants were deployed for persistence, profiling, and lateral movement.
Researchers said OceanLotus began a supply-chain attack against FireAnt MetaKit around October 2025, compromising its update server to target selected stock investors in Vietnam. The attackers abused the software's legitimate update mechanism to deliver a malicious downloader that led to deployment of the SPECTRALVIPER backdoor.
ESET reported that OceanLotus targeted an unnamed Vietnamese infrastructure and transport construction corporation, with the intrusion beginning in late 2024. The initial access vector was suspected to involve remote code execution flaws in a public-facing Microsoft SQL Server.
On 2026-06-11, reporting on ESET's findings publicly attributed two recent cyber espionage campaigns to the Vietnam-aligned threat actor OceanLotus. The disclosed campaigns centered on the SPECTRALVIPER backdoor and targeted domestic Vietnamese entities including stock investors and a construction-sector organization.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.