Thursday, July 2, 2026
  • About Web3Wire
  • Web3Wire NFTs
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Media Network
  • RSS Feed
  • Contact Us
Web3Wire
No Result
View All Result
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
  • Home
  • Web3
    • Latest
    • AI
    • Business
    • Blockchain
    • Cryptocurrencies
    • Decentralized Finance
    • Metaverse
    • Non-Fungible Token
    • Press Release
  • Technology
    • Consumer Tech
    • Digital Fashion
    • Editor’s Choice
    • Guides
    • Stories
  • Coins
    • Top 10 Coins
    • Top 50 Coins
    • Top 100 Coins
    • All Coins
  • Exchanges
    • Top 10 Crypto Exchanges
    • Top 50 Crypto Exchanges
    • Top 100 Crypto Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks
  • Events
  • News
    • Latest Crypto News
    • Latest DeFi News
    • Latest Web3 News
No Result
View All Result
Web3Wire
No Result
View All Result
Home Artificial Intelligence

Vietnam-aligned OceanLotus pivots to spy on domestic targets as it takes a more selective approach abroad, ESET Research finds

June 11, 2026
in Artificial Intelligence, GlobeNewswire, Web3
Reading Time: 7 mins read
5
SHARES
257
VIEWS
Share on TwitterShare on LinkedInShare on Facebook
  • From mid-2024 to February 2026, Vietnam-aligned APT group OceanLotus compromised the network of a Vietnamese infrastructure and transport construction corporation with its signature implant, SPECTRALVIPER. 
  • From October 2025 to March 2026, OceanLotus carried out a supply-chain attack leveraging FireAnt MetaKit, a software platform widely used by stock market investors in Vietnam. 
  • Domestic targets represent a shift in operational patterns for this group.
  • OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene as Vietnamese authorities have embarked upon a major crusade against corruption.

BRATISLAVA, Slovakia and MONTREAL, June 11, 2026 (GLOBE NEWSWIRE) — ESET Research’s tracking of OceanLotus activities from 2024–2026 has revealed a shift in operational focus as the Vietnam-aligned group adopted a more selective approach to external operations while placing increasing emphasis on domestic espionage. ESET researchers identified two distinct campaigns involving the SPECTRALVIPER backdoor: a supply-chain attack targeting stock market investors in Vietnam, and a prolonged espionage operation against a Vietnamese infrastructure and transport construction company.

Whether the shift represents a temporary adjustment or a long-term strategic change remains unclear; however, this 15-year-old APT group continues to demonstrate aggressive tactics and a level of craftiness in its tooling. OceanLotus is known for continuously innovating and expanding its arsenal of Windows and Linux backdoors, often implementing unique network protocols or tailoring the data collection capabilities to specific operational objectives.

Between 2017 and 2020, OceanLotus attracted significant public attention following multiple reports detailing its cyberespionage activities. These included large-scale watering-hole attacks targeting Southeast Asia in 2017–2018, intrusions into corporations such as BMW and Hyundai in 2019, and the targeting of a Vietnamese dissident in Germany that same year. The group was also linked to operations against human rights defenders between 2019 and 2020, as well as espionage targeting the Wuhan municipal government in 2020. However, the group’s operations faced a setback in 2020 when Facebook publicly identified the company believed to be used as a front for OceanLotus. Following this exposure, public reporting on the group diminished significantly, and its activities received comparatively little attention for several years.

The first campaign involved the newly discovered compromise of an infrastructure and transport construction corporation. This intrusion began in mid-2024 and persisted through January 2026. The second campaign was a supply-chain attack that began in late 2025 and continued until March 2026. In this operation, OceanLotus compromised the update server of FireAnt MetaKit, a Vietnamese stock investment platform, and replaced legitimate software updates with a malicious payload that ultimately deployed SPECTRALVIPER. This campaign appears to have targeted stock investors and may be linked to Vietnam’s recent efforts to promote securities market reforms, suggesting a possible connection to domestic monitoring or investigative objectives.

In both cases, OceanLotus deployed its signature backdoor, SPECTRALVIPER, on victim’s systems. Notably, an operational security lapse resulted in run-time type information names being left intact in a SPECTRALVIPER sample, enabling us to reconstruct aspects of the backdoor’s internal architecture. Despite the broad potential impact of such an attack, ESET observed only a few individuals who ultimately received SPECTRALVIPER, indicating selective targeting.

Overall, the available evidence points to a potential shift in OceanLotus’s operational patterns. Since the exposure of its physical front company in 2020, the group appears to have adopted a more selective approach to foreign espionage while placing increasing emphasis on domestic targets.

It is worth noting that OceanLotus’s latest activities seem to align with various recent developments taking place on Vietnam’s domestic scene. In recent years, Vietnamese authorities have embarked upon a major crusade against corruption — a program baptized Blazing Furnace. Similar to Xi Jinping’s big anti-corruption push in China, this effort, launched by the Communist Party of Vietnam, is intended to demonstrate to the population that the party is willing and able to clean up its ranks to maintain its legitimacy. In this context, it seems likely that Vietnam’s security apparatus is now deploying increasingly important resources to fight corruption (and financial crime more broadly). ESET believes that OceanLotus could be somehow associated with these efforts, and that this may be another reason behind the group’s apparent refocus on domestic intelligence and surveillance.

OceanLotus, also known as APT32, is a cyberespionage group reportedly aligned with the interests of the Vietnamese government. According to ESET telemetry, activity attributed to this group dates back to 2012, and possibly earlier. OceanLotus mainly targets China and Southeast Asia (with a focus on Vietnam); it has been associated with a variety of operations, ranging from a massive digital profiling campaign to highly targeted attacks against Vietnamese human-rights activists.

For more details about OceanLotus and its latest campaign, check out the ESET Research blogpost, “OceanLotus: From external espionage to domestic targeting,” on WeLiveSecurity.com. Make sure to follow ESET Research on Twitter (today known as X), BlueSky, and Mastodon for the latest news from ESET Research.

About ESET

ESET® provides cutting-edge cybersecurity to prevent attacks before they happen. By combining the power of AI and human expertise, ESET stays ahead of emerging global cyberthreats, both known and unknown — securing businesses, critical infrastructure, and individuals. Whether it’s endpoint, cloud, or mobile protection, our AI-native, cloud-first solutions and services remain highly effective and easy to use. ESET technology includes robust detection and response, ultra-secure encryption, and multifactor authentication. With 24/7 real-time defense and strong local support, we keep users safe and businesses running without interruption. The ever-evolving digital landscape demands a progressive approach to security: ESET is committed to world-class research and powerful threat intelligence, backed by R&D centers and a strong global partner network. For more information, visit http://www.eset.com or follow our social media, podcasts, and blogs.

About Web3Wire
Web3Wire – Information, news, press releases, events and research articles about Web3, Metaverse, Blockchain, Artificial Intelligence, Cryptocurrencies, Decentralized Finance, NFTs and Gaming.
Visit Web3Wire for Web3 News and Events, Block3Wire for the latest Blockchain news and Meta3Wire to stay updated with Metaverse News.

ShareTweet1ShareSendShare2
Previous Post

Aviator Game India 2026: 1Win Launched Aviator Game Bonus Offers In India

Next Post

Best Gold IRA for Beginners 2026: Top Gold IRA Providers Ranked and Compared in New Report

Related Posts

Vadzo Imaging Positions Falcon-544CRS Point of Care Camera with Wake-on-Motion for Portable Diagnostic Applications

Vadzo's Falco -544CRS is a 5MP USB 3.2 colo came a built o the O semi AR0544 Hype Lux LP se so , combi i g Wake-o -Motio ult a-low powe sta dby, e ha ced Dy amic Ra ge eDR, a d Li e I te leaved HDR with...

Read moreDetails

Vadzo Imaging Validates AR2020 20MP Monochrome Camera Series for High Accuracy Barcode Decoding and OCR Applications

The Falco -2020MRS a d Bolt-2020MRS a e 20MP mo och ome olli g shutte came a p oducts built o the O semi Hype Lux AR2020 se so . They a e validated fo ba code decodi g, OCR, docume t sca i g, label i spectio , a...

Read moreDetails

Marketing Operations Software Company Q:chi Celebrates 25 Years in Business

SWINDON, UK / ACCESS Newswi e / July 1, 2026 / Q:chi, the UK-based e te p ise softwa e compa y specialisi g i ma keti g ope atio s automatio a d cha el pa t e i ce tive p og amme ma ageme t, is celeb...

Read moreDetails

Brevo Makes Structural Bet on Where Senior Marketing Leadership is Headed in the AI Era

Austi , TX, July 01, 2026 (GLOBE NEWSWIRE) -- B evo, a leadi g custome e gageme t platfo m, today amed I ke Kuhlma -Rhi ow as Chief Ma keti g Office a d Ge e al Ma age , Self-Se ve, the la gest pa t of the ...

Read moreDetails

Applied Digital Delivers Second Building at Polaris Forge 1

DALLAS, July 01, 2026 (GLOBE NEWSWIRE) -- Applied Digital (NASDAQ: APLD), a desig e , builde , a d ope ato of high-pe fo ma ce, sustai ably e gi ee ed data ce te s a d colocatio se vices fo a tificial i tellige ce, cloud, etwo ki...

Read moreDetails

VSORA enters a new phase, as Ardian joins its shareholder base

MEUDON-LA-FORÊT, F a ce, July 01, 2026 (GLOBE NEWSWIRE) -- VSORA, a F e ch semico ducto compa y desig i g cutti g-edge AI i fe e ce p ocesso s, today a ou ced the st e gthe i g of its fu di g ou d. This...

Read moreDetails

G6 Hospitality Launches AI-Powered Video Tours to Elevate Guest Booking Experience

DALLAS, July 01, 2026 (GLOBE NEWSWIRE) -- G6 Hospitality, pa e t compa y of Motel 6 a d Studio 6 b a ds, today a ou ced the lau ch of Visio 360, a i ovative subsc iptio offe i g that delive s p ofessio al-quality video tou...

Read moreDetails

Kharon Named “Risk Management Company of the Year” By SupplyTech Breakthrough

LOS ANGELES, July 01, 2026 (GLOBE NEWSWIRE) -- SupplyTech B eakth ough, a leadi g i depe de t ma ket i tellige ce o ga izatio that evaluates a d ecog izes sta dout tech ology compa ies, p oducts a d se vices i the supply chai tech...

Read moreDetails

Row64 and Carahsoft Partner to Deliver Real-Time Operational Intelligence to the Public Sector

CHEYENNE, Wyo. a d RESTON, Va., July 01, 2026 (GLOBE NEWSWIRE) -- Row64, develope s of the ope atio al i tellige ce solutio fo eal-time decisio s, a d Ca ahsoft Tech ology Co p., The T usted Gove me t IT Solutio s P ovide ®, today a...

Read moreDetails

Planisware – Monthly information relating to the total number of shares and voting rights making-up the share capital – June 2026

Mo thly i fo matio elati g to the total umbe of sha es a d voti g ights maki g-up the sha e capital I fo matio me suelle elative au omb e total d’actio s et de d oits de vote composa t le capital social A ticle...

Read moreDetails
Web3Wire NFTs - The Web3 Collective

Web3Wire, $W3W Token and .w3w tld Whitepaper

Web3Wire, $W3W Token and .w3w tld Whitepaper

Claim your space in Web3 with .w3w Domain!

Web3Wire

Trending on Web3Wire

  • Top Cross-Chain DeFi Solutions to Watch by 2025

    154 shares
    Share 62 Tweet 39
  • GENISOM AI Debuts at ICRA 2026 with Full-Stack Embodied Intelligence System

    46 shares
    Share 18 Tweet 12
  • Top Layer 1 Crypto Projects to Watch in 2025

    22 shares
    Share 9 Tweet 6
  • Understanding Soulbound Tokens SBT Their Definition and Significance

    69 shares
    Share 28 Tweet 17
  • Unifying Blockchain Ecosystems: 2024 Guide to Cross-Chain Interoperability

    174 shares
    Share 70 Tweet 44
Join our Web3Wire Community!

Our newsletters are only twice a month, reaching around 10000+ Blockchain Companies, 800 Web3 VCs, 600 Blockchain Journalists and Media Houses.


* We wont pass your details on to anyone else and we hate spam as much as you do. By clicking the signup button you agree to our Terms of Use and Privacy Policy.

Web3Wire Podcasts

Upcoming Events

There are currently no events.

Latest on Web3Wire

  • Vadzo Imaging Positions Falcon-544CRS Point of Care Camera with Wake-on-Motion for Portable Diagnostic Applications
  • Vadzo Imaging Validates AR2020 20MP Monochrome Camera Series for High Accuracy Barcode Decoding and OCR Applications
  • Marketing Operations Software Company Q:chi Celebrates 25 Years in Business
  • Brevo Makes Structural Bet on Where Senior Marketing Leadership is Headed in the AI Era
  • Applied Digital Delivers Second Building at Polaris Forge 1

RSS Latest on Block3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Covo Finance: Revolutionary Crypto Leverage Trading Platform
  • WorldStrides and HEX Announce Partnership to Offer High School and University Students Innovative Courses Designed to Improve Their Outlook in the Digital Age

RSS Latest on Meta3Wire

  • The Algorithmic Monographs: A Five-Volume Civil Code for the Age of Autonomous Intelligence
  • Ali Sadhik Shaik: Practitioner, Scholar, and Author – Focused on the Governance of Intelligent Systems
  • The Klyrox Protocol: A Decentralized Framework to Close the AI Accountability Gap
  • Thumbtack Honored as a 2023 Transform Awards Winner
  • Accenture Invests in Looking Glass to Accelerate Shift from 2D to 3D
Web3Wire

Web3Wire is your go-to source for the latest insights and updates in Web3, Metaverse, Blockchain, AI, Cryptocurrencies, DeFi, NFTs, and Gaming. We provide comprehensive coverage through news, press releases, event updates, and research articles, keeping you informed about the rapidly evolving digital world.

  • About Web3Wire
  • Founder’s Note
  • Web3Wire NFTs – The Web3 Collective
  • .w3w TLD
  • $W3W Token
  • Web3Wire DAO
  • Event Partners
  • Community Partners
  • Our Media Network
  • Media Kit
  • RSS Feeds
  • Contact Us

Crypto Coins

  • Top 10 Coins
  • Top 50 Coins
  • Top 100 Coins
  • All Coins – Marketcap
  • Crypto Coins Heatmap

Crypto Exchanges

  • Top 10 Exchanges
  • Top 50 Exchanges
  • Top 100 Exchanges
  • All Crypto Exchanges

Crypto Stocks

  • Blockchain Stocks
  • NFT Stocks
  • Metaverse Stocks
  • Artificial Intelligence Stocks

Web3Wire Whitepaper | Tokenomics

Web3 Resources

  • Top Web3 and Crypto Youtube Channels
  • Latest Crypto News
  • Latest DeFi News
  • Latest Web3 News

Blockchain Resources

  • Blockchain and Web3 Resources
  • Decentralized Finance (DeFi) – Research Reports
  • All Crypto Whitepapers

Metaverse Resources

  • AR VR and Metaverse Resources
  • Metaverse Courses
Claim your space in Web3 with .w3w!

The Klyrox Protocol | The Algorithmic Monographs

Top 50 Web3 Blogs and Websites
Web3Wire Podcast on Spotify Web3Wire Podcast on Amazon Music 
Web3Wire - Web3 and Blockchain - News, Events and Press Releases | Product Hunt
Web3Wire on Google News

Media Portfolio: Block3Wire | Meta3Wire

  • Privacy Policy
  • Terms of Use
  • Disclaimer
  • Sitemap
  • For Search Engines
  • Crypto Sitemap
  • Exchanges Sitemap

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Coins
    • Top 10 Cryptocurrencies
    • Top 50 Cryptocurrencies
    • Top 100 Cryptocurrencies
    • All Coins
  • Exchanges
    • Top 10 Cryptocurrency Exchanges
    • Top 50 Cryptocurrency Exchanges
    • Top 100 Cryptocurrency Exchanges
    • All Crypto Exchanges
  • Stocks
    • Blockchain Stocks
    • NFT Stocks
    • Metaverse Stocks
    • Artificial Intelligence Stocks

© 2024 Web3Wire. We strongly recommend our readers to DYOR, before investing in any cryptocurrencies, blockchain projects, or ICOs, particularly those that guarantee profits.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.