OceanLotus Turns SPECTRALVIPER on Vietnamese Investors and a Construction Firm
Two campaigns, one toolset. The Vietnam-aligned crew spent eighteen months inside a state-linked infrastructure builder before pivoting to a supply chain hit on retail stock investors.

Key points
- OceanLotus, also tracked as APT32, has been linked to two parallel campaigns targeting Vietnamese entities with a backdoor called SPECTRALVIPER.
- The first was a prolonged intrusion at a Vietnamese infrastructure and transport construction corporation, running from mid-2024 through February 2026.
- The second was a supply chain attack on software used by retail stock investors, turning a routine update into a SPECTRALVIPER dropper.
- The same loader chain and side-loading technique connects both campaigns.
- No breach notification has surfaced under Vietnam's Personal Data Protection Decree.
What is SPECTRALVIPER and why does it keep showing up?
SPECTRALVIPER is a backdoor capable of shellcode injection and token impersonation, first dissected by researchers in 2023 and consistently linked to OceanLotus since. It's not new, but it's being refined. The loaders observed in both the 2025 and 2026 clusters reuse the same side-loading chain against legitimate Windows binaries, with command-and-control traffic wrapped in HTTPS to blend with ordinary web noise. That combination is OceanLotus's signature, and it's worked twice in the same eighteen-month window.
What happened at the construction firm?
The construction target is described as a Vietnamese infrastructure and transport corporation with ties to state-backed civil works. Operators got in around mid-2024 and held access through February 2026, rotating loaders and infrastructure to stay quiet. That's not opportunistic. It's a deliberate collection program against an organization that Hanoi would plausibly want watched.
What's still not public: the number of records exposed, the categories of data taken, or whether the access was used for anything beyond collection.
Should you worry about the investor supply chain attack?
This one is broader in potential reach. OceanLotus poisoned the update channel of a software product used by retail stock investors. Users who ran what looked like a signed update got a backdoor wired for credential theft and follow-on tooling instead. It's a supply chain attack in the same family as the campaigns we covered in the Miasma Campaign on 2 June 2026 and the Hades Campaign on 9 June 2026, even if the sector and the actor differ.
What hasn't emerged: whether brokerage credentials were leveraged for unauthorized trades, or how many investors were hit.
What this means outside Vietnam
Attribution fits the established OceanLotus playbook: domestic surveillance of entities of interest to Hanoi, plus financially adjacent targets where investor data and trading behavior carry intelligence value. The group has a documented history of expanding to ASEAN neighbors and regional media organizations. A SPECTRALVIPER build tested for eighteen months against a hardened enterprise target is a more capable tool than the one researchers documented in 2023.
Vietnam's Personal Data Protection Decree obliges data controllers to report incidents to the Ministry of Public Security's A05 cybersecurity department. A05 has not commented publicly, and no vendor advisory has appeared at time of writing. If investor losses surface, that silence will become a compliance question quickly.
What affected users should do
- If you use Vietnamese retail trading software, verify installer hashes against your vendor's published signatures and reinstall from a clean source if anything looks off.
- Rotate brokerage and email credentials from a known-good device and enable hardware-backed multi-factor authentication where your broker supports it.
- Hunt for unsigned DLLs loaded by legitimate binaries in
%APPDATA%and%PROGRAMDATA%, the side-loading pattern that is SPECTRALVIPER's tell. - Review outbound HTTPS connections to low-reputation domains registered in the last twelve months.



