SUBJECT PROFILE
ESET Research disclosed on June 11, 2026 that OceanLotus (APT32) has undergone a significant strategic pivot toward domestic espionage inside Vietnam, marking a departure from its historically external targeting of China and Southeast Asian governments. Two distinct 2024–2026 campaigns were revealed: a 15-month intrusion into a Vietnamese infrastructure and transport construction corporation, and a precision supply-chain attack against FireAnt MetaKit — a stock market data platform — that selectively delivered the SPECTRALVIPER backdoor to a handful of high-value investors linked to Vietnam's ongoing financial market investigations. Researchers assess OceanLotus is now acting as a digital surveillance arm of the Vietnamese state's anti-corruption apparatus.
State-directed espionage — assessed domestic surveillance in support of Vietnam's 'Blazing Furnace' anti-corruption campaign and financial market oversight
OPERATIONAL HISTORY
T1195 (Supply Chain Compromise — FireAnt MetaKit update server hijack), T1190 (Exploit Public-Facing Application — suspected RCE on Microsoft SQL Server for initial access), T1574 (DLL Side-Loading via DtlCrashCatch.dll / IntelAudioService.exe / Toolbox.exe), T1055 (Process Injection into OneDrive.Sync.Service.exe), T1071 (C2 over HTTPS with Cookie-header beacon encoding), T1090 (Named pipe lateral movement orchestration between SPECTRALVIPER instances), T1027 (Obfuscated Files — multi-layer obfuscation on downloaders), T1078 (Valid Accounts for persistence)
KNOWN INFRASTRUCTURE
Compromised FireAnt MetaKit update server (metakit.fireant[.]vn); C2 domains: financemachinelearning[.]com (FireAnt campaign), gatewayrvcenter[.]com (infrastructure campaign); staging IPs: 139.162.11[.]152, 142.91.98[.]77; SPECTRALVIPER backdoor (HTTPS C2, zd_cs_pm= cookie prefix); malicious DLL: DtlCrashCatch.dll; signed-binary abuse: IntelAudioService.exe, OneDrive.Sync.Service.exe