Threat reportSupply ChainTL-2026-0795
OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors
OceanLotus (APT32) Supply-Chain Compromise of FireAnt (TL-2026-0795), also tracked as FireAnt MetaKit supply-chain attack, is a high-severity supply-chain compromise, first published 2026-06-14 and last reviewed 2026-08-28. It is attributed to APT32 (Vietnam) with high confidence, affects FireAnt FireAnt MetaKit, maps to 28 MITRE ATT&CK techniques (T1021, T1027, T1033), and is covered by 9 detection rules and 35 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 28MITRE ATT&CK
- Actors
- 1APT32
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 35Indicators of compromise
Key facts for TL-2026-0795
- Threat ID
- TL-2026-0795
- Also known as
- FireAnt MetaKit supply-chain attack, Blazing Furnace-aligned OceanLotus campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- Last reviewed
- Attribution
- APT32
- Attribution confidence
- HIGH
- Nation-state nexus
- Vietnam
- Motivation
- ESPIONAGE
- Target sectors
- financial, fintech, stock-investing, government, infrastructure, construction, transportation
- Target regions
- Vietnam, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 35
- Updates
- 2026-08-28 · revalidated 1× · latest source
Malware and tooling in OceanLotus (APT32) Supply-Chain Compromise of FireAnt
Malware and tooling: SPECTRALVIPER
How OceanLotus (APT32) Supply-Chain Compromise of FireAnt works
OceanLotus (APT32) compromised the unauthenticated HTTP update channel of FireAnt MetaKit, a Vietnam-based stock-investing data component, to deliver trojanized setup.exe payloads that side-load and inject the SPECTRALVIPER backdoor into OneDrive.Sync.Service.exe. The selectively-targeted campaign ran October 2025 through March 2026 against individuals tied to Vietnam's anti-corruption and financial-market scrutiny.
OceanLotus (APT32), a threat actor aligned with Vietnamese state interests and active since at least 2012, conducted a supply-chain compromise of FireAnt MetaKit — a fintech software component that feeds real-time market data into trading platforms such as AmiBroker and MetaTrader for Vietnamese stock investors. The MetaKit update mechanism fetched its update manifest (metakit.fireant[.]vn/Software/version.xml) and binary (setup.exe) over unencrypted HTTP with no TLS, no code-signature validation, and no integrity verification, allowing the attacker to substitute a malicious downloader that the legitimate Metakit.exe component executed silently.
The trojanized setup.exe first profiled the victim host and reported to a staging server, enabling selective delivery of the second stage only to individuals of interest rather than mass infection. The second stage established persistence and evasion through DLL side-loading: a legitimately signed executable dtlupdate.exe renamed to IntelAudioService.exe side-loaded a malicious DtlCrashCatch.dll loader, which decoded and injected the SPECTRALVIPER backdoor into the legitimate OneDrive.Sync.Service.exe process.
SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor first publicly documented by Elastic Security Labs in 2023 (intrusion set REF2754). It supports PE loading/injection, shellcode injection, file upload/download, file and directory manipulation, token impersonation, and host reconnaissance, and can communicate in either HTTPS or named-pipe mode. In this campaign it beaconed over HTTPS to financemachinelearning[.]com (a domain crafted to blend with stock-market traffic), embedding encrypted host information inside an HTTP Cookie header (the cookie key evolved from euconsent-v2= in prior operations to zd_cs_pm= in the FireAnt campaign). Lateral movement uses an orchestration model in which an orchestrator instance relays commands to other infected hosts over named pipes; recovered RTTI class names include XGU::Pivot, XGU::Pivot::Internal::WaitNew_RemotePipe, ProcessManager/ProcessReflector, and Feature.
The campaign evolved over time: the initial 2 October 2025 sample was an unobfuscated test build with hardcoded URLs and reused infrastructure, while builds from roughly 17 October 2025 onward were heavily obfuscated, used API-based downloads, and rotated to fresh C2 infrastructure. The operators also migrated staging servers (from 139.162.11[.]152 to 142.91.98[.]77). A parallel OceanLotus operation (November 2024–February 2026) compromised a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE, deploying SPECTRALVIPER variants that side-load via the signed Toolbox.exe (requiring a -uiDll parameter) under names such as Genuine.exe, Updater.exe and AutoCAD242.exe. Targeting of stock investors coincided with Vietnam's October 2025 bond-reporting fraud revelations and the broader anti-corruption drive, leading researchers to assess OceanLotus may be acting as a digital arm of the state's domestic surveillance apparatus. No malicious updates have been observed since 9 March 2026, suggesting the FireAnt operation has concluded. No CVE was assigned; the root cause is insecure-by-design update delivery (no TLS, no signature, no integrity check).
MITRE ATT&CK techniques used in TL-2026-0795
Lateral Movement
T1021 Remote Services; T1570 Lateral Tool Transfer
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading; T1055 Process Injection; T1134 Access Token Manipulation; T1553.002 Subvert Trust Controls
Discovery
T1033 System Owner/User Discovery; T1082 System Information Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204.002 User Execution
Command and Control
T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel
Collection
Initial Access
T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise
execution
T1559 Inter-Process Communication
stealth
Persistence
T1574.002 Hijack Execution Flow
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure
Affected products and versions in OceanLotus (APT32) Supply-Chain Compromise of FireAnt
- FireAnt — FireAnt MetaKit
Vulnerable versions: update channel served via metakit.fireant.vn over HTTP, Oct 2025-Mar 2026
Fixed in: pending vendor fix adding TLS + signature validation - Microsoft — Windows (OneDrive.Sync.Service.exe injection target)
Vulnerable versions: Windows x64 hosts running FireAnt MetaKit
Remediation for OceanLotus (APT32) Supply-Chain Compromise of FireAnt
Patches
- Apply FireAnt MetaKit updates that add TLS, code-signing and integrity validation once published by the vendor
Immediate actions
- Block all listed C2 domains and IPs (financemachinelearning[.]com, gatewayrvcenter[.]com, etc.) at perimeter and DNS
- Hunt for IntelAudioService.exe / DtlCrashCatch.dll side-loading pairs and SPECTRALVIPER injection into OneDrive.Sync.Service.exe
- Isolate hosts running FireAnt MetaKit updated between October 2025 and March 2026 and inspect for setup.exe of listed hashes
- Inspect outbound HTTPS for anomalous Cookie headers (zd_cs_pm=) to finance-themed domains
Workarounds
- Disable or block the MetaKit auto-update channel (metakit.fireant[.]vn) until secure update delivery is confirmed
- Source MetaKit updates only over a verified out-of-band channel
Longer-term hardening
- Deploy EDR with behavioral detection for DLL side-loading and process injection into signed system processes
- Enforce application allowlisting to prevent execution of unsigned/renamed loaders
- Hunt for unexpected named-pipe inter-host communication consistent with the XGU::Pivot orchestration model
- Require vendors to deliver software updates over TLS with code-signature and integrity validation
Weaknesses (CWE) in OceanLotus (APT32) Supply-Chain Compromise of FireAnt
Timeline of OceanLotus (APT32) Supply-Chain Compromise of FireAnt
- C2 domain power-sync-services[.]com first observed (103.119.47[.]104), part of OceanLotus infrastructure staging.
- Parallel OceanLotus espionage operation begins against a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE.
- C2 domain mxprodesign[.]com (166.88.77[.]186) first observed — the earliest known infrastructure ESET links to the SPECTRALVIPER cluster.
- C2 domains gatewayrvcenter[.]com (139.180.128[.]42) and coachcybersecurity[.]com (139.99.33[.]239) first observed.
- First malicious payload delivered via the FireAnt MetaKit update URL (metakit.fireant[.]vn/Software/setup.exe); initial unobfuscated test build using staging server 139.162.11[.]152.
- C2 domain leadingfilipinoteams[.]com (38.60.245[.]37) first observed supporting the campaign.
- Stable, heavily obfuscated SPECTRALVIPER builds appear using API-based downloads and fresh C2 infrastructure; Cookie key changes to zd_cs_pm=.
- Primary beacon domain financemachinelearning[.]com first observed (194.68.26[.]241, M247 Europe).
- Operators migrate the staging server from 139.162.11[.]152 to 142.91.98[.]77 (LEASEWEB Singapore).
- Corporate infrastructure espionage operation activity ends (November 2024–February 2026 window).
- Last malicious FireAnt MetaKit update observed; no further malicious updates seen afterward, suggesting the operation concluded.
- Public disclosure of the OceanLotus FireAnt MetaKit supply-chain attack and SPECTRALVIPER campaigns by ESET and security press.
Update history for TL-2026-0795
- 2026-08-28 — OceanLotus (APT32) Shifts to Domestic Vietnamese Targeting with SPECTRALVIPER Backdoor and FireAnt Supply-Chain Compromise: What changed No severity/exploitability/status change — both remain HIGH/ACTIVE/ACTIVE. Adds MITRE sub-technique granularity (new T1204.002 User Execution, T1553.002 Subvert Trust Controls/Code Signing, T1571 Non-Standard Port; plus sub-tec
Sources cited for OceanLotus (APT32) Supply-Chain Compromise of FireAnt
- OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors
- OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack
- OceanLotus: From external espionage to domestic targeting
- Elastic charms SPECTRALVIPER
- New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies
- OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor
- OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Attack
Detection coverage for TL-2026-0795
As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0795 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.