Skip to content
The Coolest Info

The Coolest Info

Subscribe
  • News
  • Crypto Predictions
The Coolest Info

The Coolest Info

  • News
  • Crypto Predictions
  • Home
  • 2026
  • June
  • 11
  • OceanLotus APT Targets Vietnam Investors With SPECTRALVIPER Backdoor in Dual Campaigns
  • Security

OceanLotus APT Targets Vietnam Investors With SPECTRALVIPER Backdoor in Dual Campaigns

The TeamJune 11, 2026June 11, 202601 mins

The Vietnam-linked advanced persistent threat group OceanLotus has been tied to two separate but overlapping campaigns — one aimed at a domestic infrastructure and transport construction firm, the other targeting stock market investors. Both deployed a backdoor called SPECTRALVIPER, and together they paint a picture of an operation that ran quietly for the better part of two years.

The espionage campaign against the construction corporation stretched from mid-2024 through February 2026, suggesting patient, methodical reconnaissance rather than smash-and-grab data theft. The second campaign took a different tack: a supply chain compromise designed to reach individual investors trading on Vietnamese exchanges. That’s a notable shift — going after retail investors isn’t typical APT behavior, and it hints at either an economic intelligence motive or a broader strategy to destabilize financial confidence.

SPECTRALVIPER itself is a modular backdoor with the usual capabilities — credential harvesting, lateral movement, command-and-control communication — but what stands out is how long the operators stayed undetected. Nearly two years inside a critical infrastructure target should give any security team pause. If your threat models don’t account for APT groups with this kind of patience, it’s time to update them.

Source: The Hacker News

Tagged: Account Security APT cyber-espionage Infosecurity Europe oceanlotus software supply chain spectralviper vietnam

Post navigation

Previous: New GreatXML Zero-Day Lets Attackers Crack BitLocker via Defender Flaw
Next: Microsoft Patches BitLocker Recovery Loop Bug Hitting Windows Server 2025

Related News

NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks

June 13, 2026

Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

June 13, 2026

Chinese hackers hijack auth flow, spy on isolated network for a decade

June 13, 2026

Microsoft Patches BitLocker Recovery Loop Bug Hitting Windows Server 2025

June 11, 2026June 11, 2026

Recent Posts

  • My first 24 hours with Siri AI on the Mac
  • Bose’s latest QuietComfort Ultra are $70 off, marking a new low price
  • Microsoft hasn’t ruled out spinning off Xbox
  • NPM 12 Will Change Script Execution Behavior to Prevent Supply Chain Attacks
  • Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication

Recent Comments

No comments to show.

Archives

  • June 2026

Categories

  • Cryptocurrency
  • Security
  • Security Advisories
  • Technology
  • Crypto Predictions
Online Newspaper - News / Magazine WordPress Theme 2026.
Back To Top