# OceanLotus (APT32) Supply-Chain Compromise of FireAnt MetaKit Delivers SPECTRALVIPER Backdoor to Vietnamese Stock Investors

> OceanLotus (APT32) compromised the unauthenticated HTTP update channel of FireAnt MetaKit, a Vietnam-based stock-investing data component, to deliver trojanized setup.exe payloads that side-load and inject the SPECTRALVIPER backdoor into OneDrive.Sync.Service.exe. The selectively-targeted campaign ran October 2025 through March 2026 against individuals tied to Vietnam's anti-corruption and financial-market scrutiny.

- **Published:** 2026-06-14T00:00:00Z
- **Last reviewed:** 2026-08-28T04:56:49.987Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0795
- **ID:** TL-2026-0795
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Actor:** APT32 (Vietnam)
- **Detections:** 9 · **IOCs:** 35 (full data via the Threadlinqs MCP server — Purple tier)

## Description

OceanLotus (APT32), a threat actor aligned with Vietnamese state interests and active since at least 2012, conducted a supply-chain compromise of FireAnt MetaKit — a fintech software component that feeds real-time market data into trading platforms such as AmiBroker and MetaTrader for Vietnamese stock investors. The MetaKit update mechanism fetched its update manifest (metakit.fireant[.]vn/Software/version.xml) and binary (setup.exe) over unencrypted HTTP with no TLS, no code-signature validation, and no integrity verification, allowing the attacker to substitute a malicious downloader that the legitimate Metakit.exe component executed silently.

The trojanized setup.exe first profiled the victim host and reported to a staging server, enabling selective delivery of the second stage only to individuals of interest rather than mass infection. The second stage established persistence and evasion through DLL side-loading: a legitimately signed executable dtlupdate.exe renamed to IntelAudioService.exe side-loaded a malicious DtlCrashCatch.dll loader, which decoded and injected the SPECTRALVIPER backdoor into the legitimate OneDrive.Sync.Service.exe process.

SPECTRALVIPER is a heavily obfuscated x64 Windows backdoor first publicly documented by Elastic Security Labs in 2023 (intrusion set REF2754). It supports PE loading/injection, shellcode injection, file upload/download, file and directory manipulation, token impersonation, and host reconnaissance, and can communicate in either HTTPS or named-pipe mode. In this campaign it beaconed over HTTPS to financemachinelearning[.]com (a domain crafted to blend with stock-market traffic), embedding encrypted host information inside an HTTP Cookie header (the cookie key evolved from euconsent-v2= in prior operations to zd_cs_pm= in the FireAnt campaign). Lateral movement uses an orchestration model in which an orchestrator instance relays commands to other infected hosts over named pipes; recovered RTTI class names include XGU::Pivot, XGU::Pivot::Internal::WaitNew_RemotePipe, ProcessManager/ProcessReflector, and Feature.

The campaign evolved over time: the initial 2 October 2025 sample was an unobfuscated test build with hardcoded URLs and reused infrastructure, while builds from roughly 17 October 2025 onward were heavily obfuscated, used API-based downloads, and rotated to fresh C2 infrastructure. The operators also migrated staging servers (from 139.162.11[.]152 to 142.91.98[.]77). A parallel OceanLotus operation (November 2024–February 2026) compromised a Vietnamese infrastructure/transport construction corporation via suspected Microsoft SQL Server RCE, deploying SPECTRALVIPER variants that side-load via the signed Toolbox.exe (requiring a -uiDll parameter) under names such as Genuine.exe, Updater.exe and AutoCAD242.exe. Targeting of stock investors coincided with Vietnam's October 2025 bond-reporting fraud revelations and the broader anti-corruption drive, leading researchers to assess OceanLotus may be acting as a digital arm of the state's domestic surveillance apparatus. No malicious updates have been observed since 9 March 2026, suggesting the FireAnt operation has concluded. No CVE was assigned; the root cause is insecure-by-design update delivery (no TLS, no signature, no integrity check).

## MITRE ATT&CK

- T1583 Acquire Infrastructure
- T1584 Compromise Infrastructure
- T1195 Supply Chain Compromise
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1129 Shared Modules
- T1574 Hijack Execution Flow
- T1055 Process Injection
- T1036 Masquerading
- T1027 Obfuscated Files or Information
- T1134 Access Token Manipulation
- T1082 System Information Discovery
- T1033 System Owner/User Discovery
- T1570 Lateral Tool Transfer
- T1021 Remote Services
- T1074 Data Staged
- T1071 Application Layer Protocol
- T1573 Encrypted Channel
- T1559 Inter-Process Communication
- T1105 Ingress Tool Transfer
- T1041 Exfiltration Over C2 Channel
- T1195.002 Supply Chain Compromise
- T1204.002 User Execution
- T1574.002 Hijack Execution Flow
- T1036.005 Masquerading
- T1553.002 Subvert Trust Controls
- T1071.001 Application Layer Protocol
- T1571 Non-Standard Port

## Sources

- [OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors](https://cybersecuritynews.com/oceanlotus-apt-compromises-fireant-metakit/)
- [OceanLotus Hits Vietnam Investors With SPECTRALVIPER in FireAnt Attack](https://thehackernews.com/2026/06/oceanlotus-hits-vietnam-investors-with.html)
- [OceanLotus: From external espionage to domestic targeting](https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/)
- [Elastic charms SPECTRALVIPER](https://www.elastic.co/security-labs/elastic-charms-spectralviper)
- [New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies](https://thehackernews.com/2023/06/new-spectralviper-backdoor-targeting.html)
- [OceanLotus targets stock investors and construction firm with SPECTRALVIPER backdoor](https://www.scworld.com/brief/oceanlotus-targets-stock-investors-and-construction-firm-with-spectralviper-backdoor)
- [OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Attack](https://cyberpress.org/oceanlotus-hits-stock-investors/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0795
