Threat reportSupply ChainTL-2026-0795

OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors

highACTIVE

OceanLotus (APT32) Supply-Chain Compromise of FireAnt (TL-2026-0795), also tracked as FireAnt MetaKit supply-chain attack, is a high-severity supply-chain compromise, first published 2026-06-14 and last reviewed 2026-08-28. It is attributed to APT32 (Vietnam) with high confidence, affects FireAnt FireAnt MetaKit, maps to 28 MITRE ATT&CK techniques (T1021, T1027, T1033), and is covered by 9 detection rules and 35 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
28MITRE ATT&CK
Actors
1APT32
Detection rules
9SPL · KQL · Sigma
IOCs
35Indicators of compromise

Key facts for TL-2026-0795

Threat ID
TL-2026-0795
Also known as
FireAnt MetaKit supply-chain attack, Blazing Furnace-aligned OceanLotus campaign
Severity
HIGH
Status
ACTIVE
Category
SUPPLY_CHAIN
First published
Last reviewed
Attribution
APT32
Attribution confidence
HIGH
Nation-state nexus
Vietnam
Motivation
ESPIONAGE
Target sectors
financial, fintech, stock-investing, government, infrastructure, construction, transportation
Target regions
Vietnam, Southeast Asia
Detection rules
9
Indicators of compromise
35
Updates
2026-08-28 · revalidated 1× · latest source

Malware and tooling in OceanLotus (APT32) Supply-Chain Compromise of FireAnt

Malware and tooling: SPECTRALVIPER

How OceanLotus (APT32) Supply-Chain Compromise of FireAnt works

OceanLotus (APT32) compromised the unauthenticated HTTP update channel of FireAnt MetaKit, a Vietnam-based stock-investing data component, to deliver trojanized setup.exe payloads that side-load and inject the SPECTRALVIPER backdoor into OneDrive.Sync.Service.exe. The selectively-targeted campaign ran October 2025 through March 2026 against individuals tied to Vietnam's anti-corruption and financial-market scrutiny.

OceanLotus (APT32), a threat actor aligned with Vietnamese state interests and active since at least 2012, conducted a supply-chain compromise of FireAnt MetaKit — a fintech software component that feeds real-time market data into trading platforms such as AmiBroker and MetaTrader for Vietnamese stock investors. The MetaKit update mechanism fetched its update manifest (metakit.fireant[.]vn/Software/version.xml) and binary (setup.exe) over unencrypted HTTP with no TLS, no code-signature validation, and no integrity verification, allowing the attacker to substitute a malicious downloader that the legitimate Metakit.exe component executed silently.

The trojanized setup.exe first profiled the victim host and reported to a staging server, enabling selective delivery of the second stage only to individuals of interest rather than mass infection. The second stage established persistence and evasion through DLL side-loading: a legitimately signed executable dtlupdate.exe renamed to IntelAudioService.exe side-loaded a malicious DtlCrashCatch.dll loader, which decoded and injected the SPECTRALVIPER backdoor into the legitimate OneDrive.Sync.Service.exe process.

SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor first publicly documented by Elastic Security Labs in 2023 (intrusion set REF2754). It supports PE loading/injection, shellcode injection, file upload/download, file and directory manipulation, token impersonation, and host reconnaissance, and can communicate in either HTTPS or named-pipe mode. In this campaign it beaconed over HTTPS to financemachinelearning[.]com (a domain crafted to blend with stock-market traffic), embedding encrypted host information inside an HTTP Cookie header (the cookie key evolved from euconsent-v2= in prior operations to zd_cs_pm= in the FireAnt campaign). Lateral movement uses an orchestration model in which an orchestrator instance relays commands to other infected hosts over named pipes; recovered RTTI class names include XGU::Pivot, XGU::Pivot::Internal::WaitNew_RemotePipe, ProcessManager/ProcessReflector, and Feature.

The campaign evolved over time: the initial 2 October 2025 sample was an unobfuscated test build with hardcoded URLs and reused infrastructure, while builds from roughly 17 October 2025 onward were heavily obfuscated, used API-based downloads, and rotated to fresh C2 infrastructure. The operators also migrated staging servers (from 139.162.11[.]152 to 142.91.98[.]77). A parallel OceanLotus operation (November 2024–February 2026) compromised a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE, deploying SPECTRALVIPER variants that side-load via the signed Toolbox.exe (requiring a -uiDll parameter) under names such as Genuine.exe, Updater.exe and AutoCAD242.exe. Targeting of stock investors coincided with Vietnam's October 2025 bond-reporting fraud revelations and the broader anti-corruption drive, leading researchers to assess OceanLotus may be acting as a digital arm of the state's domestic surveillance apparatus. No malicious updates have been observed since 9 March 2026, suggesting the FireAnt operation has concluded. No CVE was assigned; the root cause is insecure-by-design update delivery (no TLS, no signature, no integrity check).

MITRE ATT&CK techniques used in TL-2026-0795

Lateral Movement

T1021 Remote Services; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Masquerading; T1055 Process Injection; T1134 Access Token Manipulation; T1553.002 Subvert Trust Controls

Discovery

T1033 System Owner/User Discovery; T1082 System Information Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter; T1129 Shared Modules; T1204.002 User Execution

Command and Control

T1071 Application Layer Protocol; T1071.001 Application Layer Protocol; T1105 Ingress Tool Transfer; T1571 Non-Standard Port; T1573 Encrypted Channel

Collection

T1074 Data Staged

Initial Access

T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.002 Supply Chain Compromise

execution

T1559 Inter-Process Communication

stealth

T1574 Hijack Execution Flow

Persistence

T1574.002 Hijack Execution Flow

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure

Affected products and versions in OceanLotus (APT32) Supply-Chain Compromise of FireAnt

  • FireAnt — FireAnt MetaKit
    Vulnerable versions: update channel served via metakit.fireant.vn over HTTP, Oct 2025-Mar 2026
    Fixed in: pending vendor fix adding TLS + signature validation
  • Microsoft — Windows (OneDrive.Sync.Service.exe injection target)
    Vulnerable versions: Windows x64 hosts running FireAnt MetaKit

Remediation for OceanLotus (APT32) Supply-Chain Compromise of FireAnt

Patches

  • Apply FireAnt MetaKit updates that add TLS, code-signing and integrity validation once published by the vendor

Immediate actions

  • Block all listed C2 domains and IPs (financemachinelearning[.]com, gatewayrvcenter[.]com, etc.) at perimeter and DNS
  • Hunt for IntelAudioService.exe / DtlCrashCatch.dll side-loading pairs and SPECTRALVIPER injection into OneDrive.Sync.Service.exe
  • Isolate hosts running FireAnt MetaKit updated between October 2025 and March 2026 and inspect for setup.exe of listed hashes
  • Inspect outbound HTTPS for anomalous Cookie headers (zd_cs_pm=) to finance-themed domains

Workarounds

  • Disable or block the MetaKit auto-update channel (metakit.fireant[.]vn) until secure update delivery is confirmed
  • Source MetaKit updates only over a verified out-of-band channel

Longer-term hardening

  • Deploy EDR with behavioral detection for DLL side-loading and process injection into signed system processes
  • Enforce application allowlisting to prevent execution of unsigned/renamed loaders
  • Hunt for unexpected named-pipe inter-host communication consistent with the XGU::Pivot orchestration model
  • Require vendors to deliver software updates over TLS with code-signature and integrity validation

Weaknesses (CWE) in OceanLotus (APT32) Supply-Chain Compromise of FireAnt

CWE-494, CWE-345, CWE-319, CWE-347, CWE-426

Timeline of OceanLotus (APT32) Supply-Chain Compromise of FireAnt

  • C2 domain power-sync-services[.]com first observed (103.119.47[.]104), part of OceanLotus infrastructure staging.
  • Parallel OceanLotus espionage operation begins against a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE.
  • C2 domain mxprodesign[.]com (166.88.77[.]186) first observed — the earliest known infrastructure ESET links to the SPECTRALVIPER cluster.
  • C2 domains gatewayrvcenter[.]com (139.180.128[.]42) and coachcybersecurity[.]com (139.99.33[.]239) first observed.
  • First malicious payload delivered via the FireAnt MetaKit update URL (metakit.fireant[.]vn/Software/setup.exe); initial unobfuscated test build using staging server 139.162.11[.]152.
  • C2 domain leadingfilipinoteams[.]com (38.60.245[.]37) first observed supporting the campaign.
  • Stable, heavily obfuscated SPECTRALVIPER builds appear using API-based downloads and fresh C2 infrastructure; Cookie key changes to zd_cs_pm=.
  • Primary beacon domain financemachinelearning[.]com first observed (194.68.26[.]241, M247 Europe).
  • Operators migrate the staging server from 139.162.11[.]152 to 142.91.98[.]77 (LEASEWEB Singapore).
  • Corporate infrastructure espionage operation activity ends (November 2024–February 2026 window).
  • Last malicious FireAnt MetaKit update observed; no further malicious updates seen afterward, suggesting the operation concluded.
  • Public disclosure of the OceanLotus FireAnt MetaKit supply-chain attack and SPECTRALVIPER campaigns by ESET and security press.

Update history for TL-2026-0795

Sources cited for OceanLotus (APT32) Supply-Chain Compromise of FireAnt

Detection coverage for TL-2026-0795

As of 2026-08-28, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0795 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
35 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats