DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 13:15:29ZSOURCES: 14CRITICAL: 18
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — wp2shell (CVE-2026-63030 + CVE-2026-60137) is being actively exploited in the wild —… /// @MsftSecIntel CRITICAL — Microsoft is tracking active exploitation of CVE-2026-63030 and CVE-2026-60137… /// @vxunderground CRITICAL — wp2shell PoCs are now floating around the internet. Public exploit code for the full… /// @FalconFeedsio CRITICAL — 🔴 Qilin ransomware group has now publicly claimed 2,035+ victims on its dark web leak… /// @TalosSecurity CRITICAL — Talos is tracking mass exploitation of wp2shell (CVE-2026-63030/CVE-2026-60137).…
18Critical Threats
18Active CVEs
10IOCs Tracked
6New Advisories
TLP:WHITETHREAT ACTOR DOSSIER // OCEANLOTUS-APT32-DOMESTIC-PIVOTFIRST SEEN: 2012

OCEANLOTUS (APT32) — DOMESTIC ESPIONAGE PIVOT

ALSO KNOWN AS: APT32, SeaLotus, APT-C-00, Canvas Cyclone, BISMUTH
FROM:DMZ INTELLIGENCE DESK
ORIGIN:Vietnam (assessed — Vietnamese government-aligned)
ATTRIBUTION:STATE-SPONSORED
STATUS:ACTIVE
FIRST OBSERVED:2012
TECHNICALRESOURCESPERSISTENCESTEALTHIMPACT
TECHNICAL82/100
RESOURCES90/100
PERSISTENCE90/100
STEALTH90/100
IMPACT82/100

ESET Research disclosed on June 11, 2026 that OceanLotus (APT32) has undergone a significant strategic pivot toward domestic espionage inside Vietnam, marking a departure from its historically external targeting of China and Southeast Asian governments. Two distinct 2024–2026 campaigns were revealed: a 15-month intrusion into a Vietnamese infrastructure and transport construction corporation, and a precision supply-chain attack against FireAnt MetaKit — a stock market data platform — that selectively delivered the SPECTRALVIPER backdoor to a handful of high-value investors linked to Vietnam's ongoing financial market investigations. Researchers assess OceanLotus is now acting as a digital surveillance arm of the Vietnamese state's anti-corruption apparatus.

State-directed espionage — assessed domestic surveillance in support of Vietnam's 'Blazing Furnace' anti-corruption campaign and financial market oversight

T1195 (Supply Chain Compromise — FireAnt MetaKit update server hijack), T1190 (Exploit Public-Facing Application — suspected RCE on Microsoft SQL Server for initial access), T1574 (DLL Side-Loading via DtlCrashCatch.dll / IntelAudioService.exe / Toolbox.exe), T1055 (Process Injection into OneDrive.Sync.Service.exe), T1071 (C2 over HTTPS with Cookie-header beacon encoding), T1090 (Named pipe lateral movement orchestration between SPECTRALVIPER instances), T1027 (Obfuscated Files — multi-layer obfuscation on downloaders), T1078 (Valid Accounts for persistence)

INFRASTRUCTURE
TRANSPORTATION
FINANCIAL SERVICES
STOCK INVESTORS
GOVERNMENT

Compromised FireAnt MetaKit update server (metakit.fireant[.]vn); C2 domains: financemachinelearning[.]com (FireAnt campaign), gatewayrvcenter[.]com (infrastructure campaign); staging IPs: 139.162.11[.]152, 142.91.98[.]77; SPECTRALVIPER backdoor (HTTPS C2, zd_cs_pm= cookie prefix); malicious DLL: DtlCrashCatch.dll; signed-binary abuse: IntelAudioService.exe, OneDrive.Sync.Service.exe

FILE DATE: NOV 2024
Operation Silent Foundation
OceanLotus maintained covert access inside a major Vietnamese infrastructure and transport construction corporation from approximately November 2024 through February 2026, deploying three distinct SPECTRALVIPER variants across hosts with differing orchestration configurations, likely via SQL Server RCE exploitation.
FILE DATE: OCT 2025
FireAnt MetaKit Supply Chain Attack
From October 2025 to March 2026, OceanLotus hijacked the FireAnt MetaKit █████████████████ selectively delivered SPECTRALVIPER to a small number of Vietnamese stock investors, assessed as linked to Vietnam's active anti-corruption and securities market reform investigations; ESET disclosed publicly on June 11, 2026.
SHARE BRIEF:✕ Post on Xin Share on LinkedIn