news.mlab.sh
Back to the feed
threat-intel

OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack

High
Summary

OceanLotus, a 15-year-old APT group with a history of targeting China and human rights activists, has been conducting a prolonged cyber espionage operation against Vietnamese entities, including a transport construction corporation and stock investors. The group utilized the SPECTRALVIPER backdoor in a supply chain attack leveraging FireAnt Metakit, and recently deployed the ZiChatBot malware via the PyPI repository. This shift in focus towards domestic espionage highlights the group's continued sophistication and aggressive tactics.

OceanLotus’s recent activity centers around a multi-faceted campaign targeting Vietnam. Initially, the group focused on espionage against Vietnamese infrastructure and transport construction companies, operating from mid-2024 to February 2026. This involved exploiting potential remote code execution vulnerabilities in Microsoft SQL servers to gain initial access and subsequently deploying the SPECTRALVIPER backdoor. A parallel campaign targeted stock investors through a supply chain attack utilizing FireAnt Metakit, a software platform, from October 2025 to March 2026. This attack leveraged a compromised update URL to deliver SPECTRALVIPER to a limited number of users, exploiting a lack of integrity validation within the Metakit software. Furthermore, the group recently resurfaced with the ZiChatBot malware, distributed via the Python Package Index (PyPI), demonstrating their ongoing operational capabilities and adaptability. The group's tactics include lateral movement and utilizing command-and-control servers for data exfiltration.

Read the full article at The Hacker News