Researchers linked multiple malware families to OceanLotus/APT32 activity, showing the group used evolving backdoors and loaders in targeted intrusions against organizations in Vietnam and the automotive sector. Earlier analysis described JEShell, a Java-based second-stage backdoor deployed alongside KerrDown, with both malware families decoding layered shellcode to install or download a Cobalt Strike Beacon implant and, in some cases, sharing command-and-control infrastructure for redundancy. JEShell used an XOR-encrypted resource to unpack shellcode and inject it either into the current Java process on 32-bit systems or into a hardcoded SysWOW64 process on 64-bit hosts.
Later reporting tied a newer intrusion set to the same actor with moderate confidence, identifying a coordinated toolchain built around the SPECTRALVIPER backdoor, P8LOADER, and the POWERSEAL PowerShell runner. In observed attacks, a malicious DLL was dropped over SMB and launched through a renamed ProcDump binary, after which DONUTLOADER injected into sessionmsg.exe to deploy SPECTRALVIPER and then conditionally execute P8LOADER or POWERSEAL. SPECTRALVIPER supported HTTP and named-pipe C2, PE loading and injection, token impersonation, file transfer, and file-system manipulation, while POWERSEAL included AMSI and ETW bypasses; identified victims included large public companies in Vietnam, including agribusiness and financial services firms.

TTPs, infrastructure, and targeting history in one profile.
10 events from the most recent confirmed update back to the earliest known activity.
Elastic identified multiple command-and-control domains tied to REF2754 that were registered between February 2022 and April 2023, indicating recent campaign infrastructure.
Elastic assessed with moderate confidence that REF2754 is a Vietnamese state-affiliated intrusion set and aligned it with Canvas Cyclone, APT32, and OceanLotus based on malware overlap, victimology, infrastructure timing, and similarities with REF4322.
Elastic Security Labs disclosed three malware families used in REF2754: the SPECTRALVIPER backdoor, the P8LOADER PE loader, and the POWERSEAL PowerShell runner.
After execution, DONUTLOADER attempted to inject into sessionmsg.exe and was configured to load the SPECTRALVIPER backdoor, then conditionally deploy P8LOADER or POWERSEAL.
The adversary renamed SysInternals ProcDump to masquerade as windbg.exe and used it with the -md flag to load the unsigned malicious DLL dbg.config containing DONUTLOADER shellcode.
In one observed intrusion, the first recorded event was creation of C:\Users\Public\Libraries\dbg.config by the System service after the file was dropped over SMB from a previously compromised endpoint.
Elastic Security Labs tracked intrusion set REF2754 targeting large public companies operating primarily within Vietnam, including a Vietnam-based agribusiness and a Vietnam-based financial services company.
During one OceanLotus intrusion, the threat actor used JEShell, a Java-based second-stage tool delivered alongside KerrDown and other implants, sometimes sharing command-and-control infrastructure for redundancy.
OceanLotus's KerrDown malware was previously publicly described in a Medium post and a Palo Alto Unit 42 post, establishing an earlier related malware family later compared with JEShell.
Various industry and media sources publicly reported multiple targeted intrusions against auto manufacturers conducted by OceanLotus, a suspected Vietnam state-sponsored threat actor.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 21 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
elastic.co
Open sourcenorfolkinfosec.com
Open sourceunit42.paloaltonetworks.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.