#APT32
OceanLotus APT32 Tactics, Malware, and TTPs Explained socprime.com/active-threa...
OceanLotus APT32 Tactics, Malware, and TTPs Explained
OceanLotus APT32 targets Southeast Asia with spearphishing, supply chain attacks, custom malware, and DLL sideloading
socprime.com
June 23, 2026 at 6:07 AM
APT32 uses GitHub to distribute Trojan.CobaltGate, disguised as pentesting tools. GitHub Actions enable remote code execution and credential theft. Multi-stage infection and obfuscation evade detection, targeting cybersecurity professionals. Enhanced repository monitoring is crucial.
April 12, 2025 at 8:19 AM
Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
Vietnamese human rights group targeted by APT32 hackers in multi-year campaign. Malware used to compromise systems and steal data.
thehackernews.com
August 29, 2024 at 4:39 PM
#APT32 has been exploiting spear-phishing to infiltrate and compromise a Vietnamese human rights organization for over four years. They deployed #CobaltStrike Beacons to steal sensitive data, including Google Chrome cookies and personal information. thehackernews.com/2024/08/viet...
Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32
Vietnamese human rights group targeted by APT32 hackers in multi-year campaign. Malware used to compromise systems and steal data.
thehackernews.com
August 30, 2024 at 12:01 AM
Dazu sollte man folgendes wissen:
Schätzungen:
Cyberarmeen/staatliche Hacker

China: 200.000 - 300.000+
Russland: 150.000 u.a. APT29, APT32 aka CozyBear, LazyBear
Deutschland: Cyberabwehr 150..noch Fragen warum die auf der Games Con sind?
September 4, 2025 at 5:16 PM
Feed: "Cyber Security News"
By: Varshini on Thursday, June 11, 2026
OceanLotus APT Targets Stock Investors in FireAnt MetaKit Supply-Chain Attack
The Vietnam-aligned threat actor OceanLotus, widely known as APT32, has shifted its operational focus from foreign targets to domestic espionage.
cyberpress.org
June 12, 2026 at 10:14 AM
Vietnamese public companies under attack! #APT32 hackers are utilizing the new SPECTRALVIPER—a hidden backdoor packed with powerful capabilities. https://thehackernews.com/2023/06/new-spectralviper-backdoor-targeting.html #cybersecurity #hacking #malware
New SPECTRALVIPER Backdoor Targeting Vietnamese Public Companies
Vietnamese public companies under attack! APT32 hackers are utilizing the new SPECTRALVIPER—a hidden backdoor packed with powerful capabilities.
thehackernews.com
June 12, 2023 at 8:46 AM
📢 Rapport Cyble H1 2026 : 3 836 attaques ransomware et paysage cyber mondial en escalade
📝 📊 **Source et contexte** : Ce rapport est publié par Cyble Res…
https://cyberveille.ch/posts/2026-07-27-rapport-cyble-h1-2026-3-836-attaques-ransomware-et-paysage-cyber-mondial-en-escalade/ #APT32 #Cyberveille
July 27, 2026 at 3:30 PM
360 ​​Advanced Threat Research Institute discovered and captured a new attack campaign by the OceanLotus (APT-C-00) threat group, also known as APT32. The campaign utilizes CD-ROM image files with malicious payloads attached to emails as delivery carriers. mp.weixin.qq.com/s?__biz=MzUy...
July 23, 2026 at 9:51 AM
I want to create fursonas for different APTs.

Yes, stuff like Fancy Bear is too obvious. We can do that one, but I don't just want cop-outs merely using the CrowdStrike naming scheme.

I want to see furry Conti. I want to see horny APT32.
August 19, 2023 at 5:09 AM
The Vietnamese hackers seem to come now in grand scale after the Chinese hacking community it seems. Are we going to see a hacker war on Github ? threatbook.io/blog/APT32-P...
APT32 Poisoning GitHub, Targeting Chinese Cybersecurity Professionals and Specific Large Enterprises
threatbook.io
January 10, 2025 at 1:38 PM
OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors
OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors
A notorious hacking group has been caught targeting stock investors in Vietnam through a supply chain attack, hijacking a popular investment software platform to deliver a powerful backdoor. The operation, carried out by OceanLotus (also known as APT32), marks a notable shift in the group’s tactics as it turns focus increasingly toward domestic targets inside the country. OceanLotus has been active since at least 2012 and is believed to be aligned with the interests of the Vietnamese government. The group has historically targeted organizations across China and Southeast Asia, but recent tracking data shows it is now placing growing emphasis on surveillance within Vietnam itself. The attack on FireAnt MetaKit represents a concerning new chapter in that ongoing shift. Welivesecurity researchers said in a report  shared with Cyber Security News (CSN) that they identified the campaign and noted that it ran from approximately October 2025 through March 2026. The group compromised the update server of FireAnt MetaKit, a widely used stock market data delivery tool, and replaced legitimate software updates with a malicious payload. This trojanized update ultimately deployed SPECTRALVIPER , OceanLotus’s signature backdoor. Despite the broad reach a supply chain attack of this kind could have, only a small subset of users actually received SPECTRALVIPER. FireAnt MetaKit update configurations (Source – Welivesecurity) This selective delivery suggests the attackers were after specific individuals, likely tied to Vietnam’s ongoing anti-corruption investigations and financial market scrutiny. That level of precision shows the operational discipline that makes this threat group so dangerous. The timing also carries important geopolitical weight. Vietnamese authorities had been conducting wide-ranging financial investigations after revelations that about 80 major companies misreported bond sales, causing a 5.5% drop in the country’s main stock index. Researchers believe OceanLotus may have been supporting those domestic investigative efforts, acting as a digital arm of the state’s surveillance apparatus. OceanLotus APT Compromises FireAnt MetaKit FireAnt is a Vietnam-based fintech company offering real-time market data, technical analysis tools, and AI-driven investment insights . MetaKit is a specialized software component within that ecosystem, designed to feed financial data directly into trading platforms like AmiBroker and MetaTrader. Download request issued by the downloader (Source – Welivesecurity) On October 2, 2025, researchers detected the first malicious payload originating from FireAnt MetaKit’s legitimate update URL at  http://metakit.fireant[.]vn/Software/setup.exe . The update configuration file lacked any integrity validation mechanism, meaning there was nothing in place to verify whether the software being delivered was genuine. Due to this gap,  Metakit.exe  silently executed the malicious downloader as if it were a routine update. The downloader then profiled the host machine and sent that data to a staging server to request the next-stage payload. IntelAudioService.exe file info (Source – Welivesecurity) The attacker’s infrastructure evolved across the campaign. Command and control servers initially used the IP  139.162.11[.]152  before migrating to  142.91.98[.]77 . SPECTRALVIPER was then delivered via DLL side-loading , using a file named  DtlCrashCatch.dll  alongside a renamed executable called  IntelAudioService.exe , which injected the backdoor into the  OneDrive.Sync.Service.exe  process. SPECTRALVIPER Backdoor: Architecture and Capabilities SPECTRALVIPER operates as a fully featured backdoor that communicates with its command and control server over HTTPS. It sends an initial beacon to a hardcoded URL, embedding encrypted host information inside the HTTP Cookie header. In this campaign, the backdoor used the domain  financemachinelearning[.]com , carefully crafted to blend into network traffic associated with stock market activity. Execution chain of the FireAnt supply-chain attack (Source – Welivesecurity) The malware supports lateral movement through an orchestration model, where one instance acts as a controller and distributes commands to other infected machines via named pipe channels. It can also inject additional binaries or shellcode received from the server into target processes. Notably, an operational security mistake left internal class names intact in one sample , giving researchers a rare window into the backdoor’s underlying architecture. Organizations relying on third-party investment tools should verify the integrity of software updates they receive, especially when those applications lack HTTPS-based update protocols. FireAnt MetaKit’s update mechanism did not use TLS encryption, leaving it exposed to interception. Unsigned and unverified software updates should always be treated with the same caution as suspicious email attachments. Indicators of Compromise (IoCs):- Type Indicator Description URL http://metakit.fireant[.]vn/Software/setup.exe Legitimate FireAnt MetaKit update URL used to deliver malicious payload URL http://metakit.fireant.vn/Software/version.xml FireAnt MetaKit update configuration file lacking integrity validation URL https://financemachinelearning[.]com/apparatus/wind/twig/statement.html SPECTRALVIPER C&C beacon URL used in the stock investor campaign IP Address 139.162.11[.]152 Initial C&C staging server (Akamai Connected Cloud) IP Address 142.91.98[.]77 Migrated C&C staging server (LEASEWEB SINGAPORE PTE. LTD.) IP Address 139.180.128[.]42 C&C IP associated with domain gatewayrvcenter[.]com (IRT-CHOOPALL-AP) IP Address 139.99.33[.]239 C&C IP associated with coachcybersecurity[.]com (OVH Singapore PTE. LTD.) IP Address 166.88.77[.]186 C&C IP associated with mxprodesign[.]com (Evyxt Enterprise) IP Address 103.119.47[.]104 C&C IP associated with power-sync-services[.]com IP Address 38.60.245[.]37 IP associated with leadingfilipinoteams[.]com (Kaopv Cloud HK Limited) IP Address 194.68.26[.]241 IP associated with financemachinelearning[.]com (M247 Europe SRL) Domain financemachinelearning[.]com SPECTRALVIPER C&C domain crafted to target stock investors Domain gatewayrvcenter[.]com SPECTRALVIPER C&C domain used in infrastructure/transport company campaign Domain coachcybersecurity[.]com SPECTRALVIPER C&C domain Domain mxprodesign[.]com SPECTRALVIPER C&C domain Domain power-sync-services[.]com SPECTRALVIPER C&C domain Domain leadingfilipinoteams[.]com C&C domain observed in the campaign File Name setup.exe Malicious downloader delivered via FireAnt MetaKit update mechanism File Name DtlCrashCatch.dll SPECTRALVIPER configured as a loader via DLL side-loading File Name IntelAudioService.exe Renamed copy of legitimate signed executable  dtlupdate.exe  used for side-loading File Name NotificationConfig.json Associated configuration file (Win64/Agent.HRA) File Name system.config.xml Associated configuration file (Win64/Agent.GFV) File Name SetupUi.dll Associated file (Win32/Agent_AGen.FHH) SHA-1 Hash D511B77459673EC42163F19E300FF1D233B6C39F setup.exe  — Win32/Agent.AIBESP SHA-1 Hash 59A8553A4F8130F576AB234E0B220BE4D4DA0E98 setup.exe  — Win32/TrojanDownloader.Agent.IKCSP SHA-1 Hash 9CA1A5C7F79882DB913534C1E62B26BCDCB9F6DD setup.exe  — Win32/TrojanDownloader.Agent.IIZSP SHA-1 Hash A8E2BBBFCB86500322D2367744FA12755AB0C165 setup.exe  — Win32/TrojanDownloader.Agent_AGen.JLSP SHA-1 Hash F74F1FEB62B662CDA489FDB2453727824E55ACB9 setup.exe  — Win32/TrojanDownloader.Agent.IJNSP SHA-1 Hash F8F8209987CA7F139DE6A62F9E6EE21BD2AE93A9 setup.exe  — Win32/TrojanDownloader.Agent.IJXSP SHA-1 Hash 19A69F856EFA811C376F68E4FEB0997B4724F8BD setup.exe  — Win32/Agent.AIBESP SHA-1 Hash 490194E9BB5128ECA8693AD9E610891C2ED185AF setup.exe  — Win32/Agent.AIBESP SHA-1 Hash 51176139B0B2220B802C1578A4994DF68DF5BCD1 setup.exe  — Win32/Agent.AICBSP SHA-1 Hash 91F042F59BE4BDCB6E5EA21B91DECD731C175B54 setup.exe  — Win32/Agent.AICBSP SHA-1 Hash A177ED0BFFEB1EFE1D9D31D72A82EF2625AE646D setup.exe  — Win32/Agent.AIBESP SHA-1 Hash B7B2D2DB544F9EEA74453CDF2B8BEEA58CF07C48 setup.exe  — Generic.CPN2WW8SP SHA-1 Hash 4AD36AD6C165B5174967020CB1A3358F78D7A283 setup.exe  — Win32/Agent.AIBESP SHA-1 Hash 57352B3CEEE32216E5AA20BAA848483D7AB5A6FB setup.exe  — Win32/Agent.AIBESP SHA-1 Hash 9BC06DF9F932746A05EE728C8B103BD3BA6BF395 setup.exe  — Generic.ETQ997N SP SHA-1 Hash 865A1739337D3303B3AB02C5E694C22B79C42B7D system.config.xml  — Win64/Agent.GFV SHA-1 Hash 41CB8CD78B8DB76563E4F972ABE817CEEE9CF9B0 DtlCrashCatch.dll  — N/A SHA-1 Hash 0037DBB0FEA981D02F6F76DE81EBAEFCB68B7D20 NotificationConfig.json  — Win64/Agent.HRA SHA-1 Hash 5D6194BB48FEBB91A10D1462461A012FAFC0918B DtlCrashCatch.dll  — Win64/Agent.HRA SHA-1 Hash B028E947150764A71DEEF498DE6F8C95ECCCB445 SetupUi.dll  — Win32/Agent_AGen.FHH Note:   IP addresses and domains are intentionally defanged (e.g.,  [.] ) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM . Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in Google . The post OceanLotus APT Compromises FireAnt MetaKit in Supply-Chain Attack on Stock Investors appeared first on Cyber Security News .
cybersecuritynews.com
June 11, 2026 at 5:54 PM
Vietnam's OceanLotus APT (APT32) pivots to domestic spying, targeting construction and finance. New campaigns include a supply-chain attack on FireAnt stock software, deploying the SPECTRALVIPER backdoor. 🇻🇳 #APT32 #OceanLotus #CyberEspionage

🌐 cyber[.]netsecops[.]io
Vietnam
The Vietnam-aligned APT group OceanLotus (APT32) is now targeting domestic entities, using its SPECTRALVIPER backdoor in a supply-chain attack against stock investors and a construction firm.
cyber.netsecops.io
June 11, 2026 at 8:43 PM
Possible APT32/Ocean Lotus Installer abusing MST Transforms
Possible APT32/Ocean Lotus Installer abusing MST Transforms
dmpdump.github.io
May 30, 2025 at 9:39 AM
OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks The OceanLotus hacker group, widely tracked as APT32, has initiated a highly targeted surveillance campaign ...

#Cyber #Security #News #Threats #cyber #security #cyber #security #news

Origin | Interest | Match
OceanLotus Hacker Group Targeting Xinchuang IT Ecosystems to Launch Supply Chain Attacks
APT32 is targeting China’s Xinchuang ecosystem, exploiting domestic IT systems to infiltrate sensitive state and industrial networks.
cybersecuritynews.com
December 8, 2025 at 1:27 PM
APT32’s SPECTRALVIPER Backdoor: How a Trusted Software Update Became a Supply-Chain Nightmare + Video

Introduction: The software update you trust might be the very thing that compromises your entire organization. Between October 2025 and March 2026, the Vietnam-aligned Advanced Persistent Threat…
APT32’s SPECTRALVIPER Backdoor: How a Trusted Software Update Became a Supply-Chain Nightmare + Video
Introduction: The software update you trust might be the very thing that compromises your entire organization. Between October 2025 and March 2026, the Vietnam-aligned Advanced Persistent Threat group APT32 (aka OceanLotus) demonstrated this grim reality by compromising the legitimate update server of FireAnt MetaKit—a popular Vietnamese stock-investment platform—and delivering their signature SPECTRALVIPER backdoor directly through the trusted update channel. What makes this attack particularly insidious is not just the technical sophistication, but the strategic pivot: APT32 has shifted from broad external espionage toward highly selective domestic intelligence operations inside Vietnam, targeting stock investors and infrastructure firms with surgical precision.
undercodetesting.com
June 16, 2026 at 10:37 AM
SPECTRALVIPER: How OceanLotus Hijacked a Stock App’s Update Server to Backdoor Investors—No Signature Check Required + Video

Introduction A routine software update for a Vietnamese stock investment platform turned into a silent cyber-espionage operation. From October 2025 to March 2026, the…
SPECTRALVIPER: How OceanLotus Hijacked a Stock App’s Update Server to Backdoor Investors—No Signature Check Required + Video
Introduction A routine software update for a Vietnamese stock investment platform turned into a silent cyber-espionage operation. From October 2025 to March 2026, the state-aligned threat actor known as OceanLotus (APT32) compromised the update server of FireAnt MetaKit, replacing legitimate software with the SPECTRALVIPER backdoor. The attack was possible because the application’s update configuration file lacked any digital signature validation mechanism—meaning the software trusted and executed the malicious payload as if it were a genuine update.
undercodetesting.com
June 12, 2026 at 3:35 AM