OceanLotus Targets Vietnam With SPECTRALVIPER Spyware

ESET researchers have attributed two 2024–2026 campaigns to the OceanLotus (APT32) group, targeting domestic Vietnamese entities: an infrastructure

CyberSecureFox

📰 Vietnam's OceanLotus APT Pivots to Domestic Spying, Hits Construction and Finance Sectors

Vietnam's OceanLotus APT (APT32) pivots to domestic spying, targeting construction and finance. New campaigns include a supply-chain attack on FireAnt stock software, deploying the SPECTRALVIPER backdoor. 🇻🇳 #APT32 #OceanLotus #CyberEspionage

🌐 cyber[.]netsecops[.]io

🔗 https://cyber.netsecops.io/articles/vietnam-apt-oceanlotus-targets-domestic-firms-spy-campaigns/?utm_sourc…

APT32 Hacker Group Attacking Cybersecurity Professionals Poisoning GitHub

The malicious Southeast Asian APT group known as OceanLotus (APT32) has been implicated in a sophisticated attack.

GBHackers Security | #1 Globally Trusted Cyber Security News Platform
#APT32 has been exploiting spear-phishing to infiltrate and compromise a Vietnamese human rights organization for over four years. They deployed #CobaltStrike Beacons to steal sensitive data, including Google Chrome cookies and personal information. https://thehackernews.com/2024/08/vietnamese-human-rights-group-targeted.html
Vietnamese Human Rights Group Targeted in Multi-Year Cyberattack by APT32

Vietnamese human rights group targeted by APT32 hackers in multi-year campaign. Malware used to compromise systems and steal data.

The Hacker News

Thanks SC Magazine, for allowing me to provide a little detail on #APT32 and some of the organised crime groups in Vietnam, alongside @WithSecureLabs' recent report on the recent use of #DarkGate #malware.

#APT #DFIR #IncidentResponse

https://www.scmagazine.com/news/hackers-target-u-s-facebook-biz-accounts-with-potent-malware-cocktail

Hackers target U.S. Facebook biz accounts with potent malware cocktail

Multiple threat actors are using a malware as a service toolset and targeting Facebook business accounts in the U.S., UK and India.

SC Media

via: @campuscodi

QiAnXin published a report on the recent attacks of #OceanLotus (#APT32) that targeted Chinese organizations throughout 2021.

The group allegedly used 3 zero-day #vulns:

+1 in an unnamed antivirus product
+2 in an unnamed workstation management system. More here (in Chinese): https://mp.weixin.qq.com/s/pd6fUs5TLdBtwUHauclDOQ | #infosec #espionage #malware

APT32 годами атакует вьетнамских правозащитников с помощью шпионского ПО #APT32, #кибершпионаж, #Вьетнам https://t.co/MMlV8kq3Xj https://t.co/fVcDCYCj3o

Источник: https://twitter.com/SecurityLabnews/status/1364837542676299777

APT32 годами атакует вьетнамских правозащитников с помощью шпионского ПО

Атаки являются частью текущей кампании, направленной на слежку за вьетнамскими правозащитниками, блоггерами и некоммерческими организациями.

Facebook Shutters Accounts Used in APT32 Cyberattacks - Facebook shut down accounts and Pages used by two separate threat groups to spread malware and con... https://threatpost.com/facebook-accounts-apt32-cyberattacks/162186/ #phishingattack #malwareattack #wateringhole #cyberattack #bangladesh #googleapps #googleplay #facebook #phishing #malware #hacks #apt32
Facebook Shutters Accounts Used in APT32 Cyberattacks

Facebook shut down accounts and Pages used by two separate threat groups to spread malware and conduct phishing attacks.

Threatpost - English - Global - threatpost.com
MacOS Users Targeted By OceanLotus Backdoor - The new backdoor comes with multiple payloads and new detection evasion tactics. https://threatpost.com/macos-users-targeted-oceanlotus-backdoor/161655/ #vietnamesecyberattack #microsoftword #oceanlotusapt #macosmalware #oceanlotus #ziparchive #backdoor #malware #payload #apt32 #macos
MacOS Users Targeted By OceanLotus Backdoor

The new backdoor variant comes with multiple payloads and new detection evasion tactics.

Threatpost - English - Global - threatpost.com