Actor Profile

OceanLotus (also tracked as APT32, SeaLotus, APT-C-00, and Canvas Cyclone) is a Vietnam-aligned advanced persistent threat group attributed by multiple vendors to conducting cyber espionage operations. The actor demonstrates sustained operational capability, conducting prolonged intrusions spanning multiple years. OceanLotus is motivated by intelligence collection targeting Vietnamese domestic entities across critical infrastructure, finance, and construction sectors, as well as stock market investors. The group exhibits sophisticated tradecraft including supply chain compromise and custom malware development, with SPECTRALVIPER representing their latest known backdoor tooling deployed from mid-2024 through February 2026.

TTPs (Tactics, Techniques, Procedures)

OceanLotus leverages a diverse set of techniques mapped to MITRE ATT&CK. Initial access is achieved via spearphishing attachments (T1566.001) and supply chain compromise. The group employs masquerading (T1036) and NTFS file attributes manipulation (T1564.004) for defense evasion. Execution relies on JavaScript (T1059.007), WMI (T1047), and signed script proxy execution via PubPrn (T1216.001). Credential access includes pass the hash (T1550.002) and registry credential harvesting (T1552.002). Discovery activities include system information collection (T1082), network share enumeration (T1135), and system owner/user discovery (T1033). Lateral movement utilizes third-party software (T1072), lateral tool transfer (T1570), and process injection (T1055). Command and control employs non-standard ports (T1571). Known malware arsenal includes Kerrdown, Cobalt Strike, SOUNDBITE, OSX_OCEANLOTUS.D, KOMPROGO, RotaJakiro, PHOREAL, WINDSHIELD, Denis, Goopy, and SPECTRALVIPER.

Targets & Patterns

OceanLotus demonstrates a clear targeting pattern focused on Vietnamese entities across multiple strategic sectors. Primary targets include infrastructure and transportation construction corporations, finance sector organizations, and stock market investors within Vietnam. The prolonged 20-month campaign (mid-2024 to February 2026) against a Vietnamese infrastructure and transport construction corporation indicates persistent intelligence collection requirements against critical national infrastructure projects. The targeting of finance sector entities and stock investors suggests economic espionage objectives, potentially seeking competitive advantage or market intelligence. The domestic focus on Vietnamese targets, combined with Vietnam-aligned attribution, suggests the actor may be conducting internal surveillance or counter-intelligence operations rather than traditional nation-state espionage against foreign adversaries.

Historical Context

OceanLotus (APT32) has been publicly tracked since at least 2014, with extensive documentation of campaigns targeting Southeast Asian governments, dissidents, foreign corporations, and journalists. The group has historically targeted Vietnamese interests alongside regional adversaries. Previous campaigns demonstrated macOS and Windows malware capabilities (OSX_OCEANLOTUS.D, Denis, PHOREAL, WINDSHIELD) and strategic web compromises. The SPECTRALVIPER backdoor represents a continuation of the group's custom malware development pattern, following tools like Kerrdown, SOUNDBITE, and KOMPROGO. The 2024-2026 infrastructure targeting campaign aligns with OceanLotus's established pattern of prolonged, persistent access operations lasting months to years. The supply chain attack methodology observed in recent activity is consistent with the group's evolution toward more sophisticated initial access vectors beyond traditional spearphishing.

Defensive Recommendations

  • Monitor for spearphishing attachments (T1566.001) with suspicious file types or macros; implement email gateway sandboxing and attachment analysis for executables and Office documents
  • Detect JavaScript execution (T1059.007) and WMI activity (T1047) via enhanced logging (Sysmon Event IDs 1, 7, 21) and behavioral analytics for scripting engines spawning unusual child processes
  • Hunt for PubPrn.vbs abuse (T1216.001) by monitoring executions of signed script proxies and correlating with network connections or file writes to non-standard locations
  • Implement pass-the-hash detection (T1550.002) through monitoring for NTLM authentication anomalies, lateral movement with privileged accounts, and unusual logon patterns across network segments
  • Deploy network segmentation and monitor for lateral tool transfer (T1570) and non-standard port C2 traffic (T1571); baseline normal administrative tool usage and flag transfers of penetration testing frameworks like Cobalt Strike
  • Conduct supply chain risk assessments for software vendors serving infrastructure and finance sectors; implement application whitelisting and code signing verification to prevent unauthorized software execution

---

# Geopolitical Context

Geopolitical Context

OceanLotus, a threat actor widely assessed to be aligned with Vietnamese state interests, has been attributed to sustained cyber espionage campaigns targeting domestic Vietnamese entities across critical infrastructure, transportation, construction, and financial sectors. The operations, spanning mid-2024 through February 2026 and employing the SPECTRALVIPER backdoor, appear consistent with internal surveillance and intelligence collection objectives. The targeting of stock investors alongside strategic infrastructure suggests a dual focus on economic intelligence and monitoring of domestic actors. Such inward-facing espionage is characteristic of authoritarian governance models seeking to maintain control over strategic industries and capital flows, and may reflect concerns about foreign influence, corruption, or political dissent within Vietnam's rapidly developing economy.

State Actor Alignment

OceanLotus (also tracked as APT32 and Canvas Cyclone) has been publicly attributed by multiple cybersecurity vendors and government agencies to Vietnamese state interests. The group's operational patterns—including sustained access to domestic targets, focus on strategic sectors, and use of custom tooling such as SPECTRALVIPER—are consistent with signals intelligence and internal security missions. Vietnam maintains active cyber capabilities under the Ministry of Public Security and military intelligence directorates, though Hanoi has not publicly acknowledged offensive cyber operations. The targeting of Vietnamese entities by a Vietnam-aligned actor underscores the dual-use nature of state cyber programs, which may serve both external espionage and domestic control functions. No international sanctions are currently in place specifically targeting Vietnamese cyber actors, though the activity may warrant monitoring under frameworks addressing transnational repression and economic espionage.

Business Impacty pro region

The campaigns highlight Vietnam's growing cyber capabilities and willingness to conduct sustained operations against domestic targets, raising concerns about digital sovereignty and the security of critical infrastructure in Southeast Asia. For regional partners and investors, the activity underscores risks associated with supply chain compromise and the potential for economic intelligence collection affecting market-sensitive information. The targeting of construction and infrastructure firms may have implications for foreign joint ventures and Belt and Road Initiative projects, given China's significant investment in Vietnamese infrastructure. European and allied firms operating in Vietnam's finance and construction sectors should reassess insider threat models and third-party risk, particularly where Vietnamese state-owned enterprises or regulated industries are involved. The prolonged timeline of the espionage operation—extending into 2026—suggests sophisticated operational security and persistent access, complicating remediation efforts and indicating potential for broader compromise across Vietnamese digital ecosystems.

Forecast

If OceanLotus maintains current operational tempo, further disclosures of domestic targeting are likely in coming months, potentially affecting investor confidence and prompting increased scrutiny of Vietnamese cybersecurity practices by international partners. Should the supply chain compromise vector prove effective, similar techniques may be adopted by other regional actors seeking access to hardened targets. If attribution becomes more politically salient—particularly in the context of US-Vietnam security cooperation or ASEAN cyber norms discussions—Hanoi may face diplomatic pressure to address transnational repression concerns, though substantive policy shifts appear unlikely in the near term. Organizations in affected sectors should anticipate persistent threat activity and prioritize detection of SPECTRALVIPER and related tooling through at least mid-2026.