OceanLotus Turns SPECTRALVIPER on Vietnamese Investors and a Construction Firm
Two campaigns, one toolset. The Vietnam-aligned crew spent eighteen months inside a state-linked infrastructure builder before pivoting to a supply chain hit on retail stock investors.

OceanLotus is back in its own backyard.
The Vietnam-aligned espionage group — also tracked as APT32 — has been linked to two parallel operations deploying SPECTRALVIPER, a 64-bit x86 backdoor that handles DLL side-loading, shellcode injection, and token impersonation. Both campaigns hit Vietnamese targets. Both ran into 2026.
The first is a long-haul intrusion at a Vietnamese infrastructure and transport construction corporation. Initial access traces back to mid-2024. Operators kept persistence through February 2026, rotating loaders and beaconing infrastructure to stay quiet inside the network for roughly eighteen months. That is not a smash-and-grab. That is a deliberate collection program against a company tied to state-backed civil works.
The second campaign is messier and broader. OceanLotus poisoned the distribution channel of a software product used by retail stock investors, turning a routine update into a SPECTRALVIPER dropper. Victims downloaded a signed-looking installer. They got a backdoor wired for credential theft and follow-on tooling.
The toolset overlap is what ties the two together. SPECTRALVIPER has been an OceanLotus signature since researchers first dissected it in 2023, and the loaders observed in both 2025–2026 clusters reuse the same side-loading chain against legitimate Windows binaries. Command-and-control traffic is wrapped in HTTPS to look like ordinary web noise.
Attribution is consistent with prior OceanLotus tasking: domestic surveillance of entities of interest to Hanoi, plus financially adjacent targets where investor data and trading behavior have intelligence value.
What is not yet public: the record count exposed at the construction firm, the specific PII categories taken from investor machines, or whether brokerage credentials were used for unauthorized trades. No breach notification has surfaced under Vietnam's Personal Data Protection Decree (PDPD), which took effect July 2023 and obliges controllers to report incidents to the Ministry of Public Security's A05 cybersecurity department within 72 hours. Expect that silence to draw scrutiny if investor losses materialize.
For anyone outside Vietnam wondering why this matters: OceanLotus has a documented history of expanding beyond domestic targets to ASEAN neighbors, automotive firms, and journalists. A refined SPECTRALVIPER build, battle-tested against a hardened enterprise victim, rarely stays regional for long.
What affected users should do:
- If you use Vietnamese retail trading software, pull installer hashes and compare against your vendor's published signatures. Reinstall from a clean source if anything looks off.
- Rotate brokerage and email credentials from a known-good device, and enable hardware-backed MFA where the broker supports it.
- Hunt for unsigned DLLs loaded by legitimate binaries in
%APPDATA%and%PROGRAMDATA%— the side-loading pattern is SPECTRALVIPER's tell. - Review outbound HTTPS to low-reputation domains registered in the last twelve months.
A05 has not commented publicly. Affected vendors have not issued advisories at time of writing.


