
The Vietnam-aligned threat actor OceanLotus, widely known as APT32, has shifted its operational focus from foreign targets to domestic espionage.
Between 2024 and 2026, the 15-year-old group launched two highly targeted campaigns using its signature SPECTRALVIPER backdoor.
One operation compromised a major Vietnamese infrastructure corporation, while a second involved a sophisticated supply-chain attack on FireAnt MetaKit, a prominent stock investment platform.
This strategic pivot strongly aligns with Vietnam’s recent “Blazing Furnace” anti-corruption crackdown.
By targeting financial sectors and corporate networks, OceanLotus appears to be supporting domestic law enforcement efforts to monitor financial crimes and corporate misconduct.
OceanLotus Hits Stock Investors
From October 2025 to March 2026, OceanLotus compromised the update infrastructure of FireAnt MetaKit. The targeted software provides real-time market data to investors using technical analysis tools like AmiBroker and MetaTrader.
The attackers successfully exploited critical security gaps in FireAnt’s update protocol, which lacked both SSL/TLS encryption and digital signature validation for its configuration files.
Because of these missing security controls, the application blindly trusted and downloaded a malicious executable disguised as a legitimate software update.
Once the software executed the malicious downloader, it triggered a multi-stage infection process:
- The downloader gathered host telemetry and sent an HTTP POST request to a staging server to fetch the next payload.
- It deployed a DLL side-loading chain using a copied, digitally signed executable to load the SPECTRALVIPER malware.
- The malware injected itself into a background process, such as the OneDrive sync service, to operate stealthily as a backdoor.
- The backdoor established a connection to an attacker-controlled domain crafted specifically to look like legitimate financial traffic.
Despite the wide reach of the FireAnt software, telemetry shows that only a highly select handful of investors actually received the final SPECTRALVIPER payload.
This suggests the threat actors were carefully filtering their victims based on specific domestic intelligence requirements.
Before the supply-chain attack, OceanLotus spent over a year inside the network of a Vietnamese infrastructure and transport construction company.
Starting in mid-2024, attackers likely exploited a remote code execution vulnerability in a publicly accessible Microsoft SQL Server to gain their initial foothold.
Once inside, the group deployed multiple variants of SPECTRALVIPER tailored to specific host environments, welivesecurity said.
Fortunately for security researchers, an operational security mistake by the attackers left Run-Time Type Information (RTTI) intact within a malware sample.
This lapse revealed the internal architecture of SPECTRALVIPER, confirming it operates as both an active backdoor and a highly capable loader.
OceanLotus continues to demonstrate aggressive tactics and deep technical craftiness. While their focus may have shifted inward to support domestic investigations, their evolving arsenal proves they remain a formidable advanced persistent threat.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.
The post OceanLotus APT Targets Stock Investors in FireAnt MetaKit Supply-Chain Attack appeared first on Cyber Security News.
Discover more from RSS Feeds Cloud
Subscribe to get the latest posts sent to your email.
