OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors — Threadlinqs Intelligence
As of 2026-06-14, OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors is a high-severity supply chain threat attributed to APT32 (Vietnam), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0795 · Severity: HIGH · Status: ACTIVE · Category: SUPPLY_CHAIN
Attribution: APT32 · Vietnam · ESPIONAGE
OceanLotus (APT32) compromised the unauthenticated HTTP update channel of FireAnt MetaKit, a Vietnam-based stock-investing data component, to deliver trojanized setup.exe payloads that side-load and
OceanLotus (APT32), a threat actor aligned with Vietnamese state interests and active since at least 2012, conducted a supply-chain compromise of FireAnt MetaKit — a fintech software component that feeds real-time market data into trading platforms such as AmiBroker and MetaTrader for Vietnamese stock investors. The MetaKit update mechanism fetched its update manifest (metakit.fireant[.]vn/Software/version.xml) and binary (setup.exe) over unencrypted HTTP with no TLS, no code-signature validation, and no integrity verification, allowing the attacker to substitute a malicious downloader that the legitimate Metakit.exe component executed silently.
The trojanized setup.exe first profiled the victim host and reported to a staging server, enabling selective delivery of the second stage only to individuals of interest rather than mass infection. The second stage established persistence and evasion through DLL side-loading: a legitimately signed executable dtlupdate.exe renamed to IntelAudioService.exe side-loaded a malicious DtlCrashCatch.dll loader, which decoded and injected the SPECTRALVIPER backdoor into the legitimate OneDrive.Sync.Service.exe process.
SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor first publicly documented by Elastic Security Labs in 2023 (intrusion set REF2754). It supports PE loading/injection, shellcode injection, file upload/download, file and directory manipulation, token impersonation, and host reconnaissance, and can communicate in either HTTPS or named-pipe mode. In this campaign it beaconed over HTTPS to financemachinelearning[.]com (a domain crafted to blend with stock-market traffic), embedding encrypted host information inside an HTTP Cookie header (the cookie key evolved from euconsent-v2= in prior operations to zd_cs_pm= in the FireAnt campaign). Lateral movement uses an orchestration model in which an orchestrator instance relays commands to other infected hosts over named pipes; recovered RTTI class names include XGU::Pivot, XGU::Pivot::Internal::WaitNew_RemotePipe, ProcessManager/ProcessReflector, and Feature.
The campaign evolved over time: the initial 2 October 2025 sample was an unobfuscated test build with hardcoded URLs and reused infrastructure, while builds from roughly 17 October 2025 onward were heavily obfuscated, used API-based downloads, and rotated to fresh C2 infrastructure. The operators also migrated staging servers (from 139.162.11[.]152 to 142.91.98[.]77). A parallel OceanLotus operation (November 2024–February 2026) compromised a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE, deploying SPECTRALVIPER variants that side-load via the signed Toolbox.exe (requiring a -uiDll parameter) under names such as Genuine.exe, Updater.exe and AutoCAD242.exe. Targeting of stock investors coincided with Vietnam's October 2025 bond-reporting fraud revelations and the broader anti-corruption drive, leading researchers to assess OceanLotus may be acting as a digital arm of the state's domestic surveillance apparatus. No malicious updates have been observed since 9 March 2026, suggesting the FireAnt operation has concluded. No CVE was assigned; the root cause is insecure-by-design update delivery (no TLS, no signature, no integrity check).
Weaknesses (CWE)
CWE-494, CWE-345, CWE-319, CWE-347, CWE-426
Target sectors: financial, fintech, stock-investing, government, infrastructure, construction, transportation
Target regions: Vietnam, Southeast Asia
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
SUPPLY_CHAIN, HIGH, threat intelligence, cybersecurity, T1583, T1584, T1195, T1190, T1059, T1129, T1574, T1055, T1036, T1027