Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
FireAnt.vn

FireAnt.vn Vendor Cyber Rating & Cyber Score

fireant.vn

No. 1 in providing services for individual and institutional investors in Vietnamese stock market


FireAnt.vn A.I CyberSecurity Scoring

FireAnt.vn
Company Information
Website:https://fireant.vn
Employees number:6
Number of followers:0
NAICS:52
Industry Type:Financial Services
Homepage:fireant.vn
FireAnt.vn Risk Score (AI oriented)
Between 750 and 799
logo
FireAnt.vnFinancial Services
Updated:
11/06/2026
786/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
FireAnt.vn Global Score (TPRM)
xxxx
logo
FireAnt.vnFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

FireAnt.vn
FireAnt.vnFair
Current Score
786Baa (FAIR)
01000
1 incidents
-16 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
786Before Incident
MAY 2026
786Before Incident
APRIL 2026
786Before Incident
MARCH 2026
785Before Incident
FEBRUARY 2026
785Before Incident
JANUARY 2026
785Before Incident
DECEMBER 2025
784Before Incident
NOVEMBER 2025
784Before Incident
OCTOBER 2025
799Before Incident
Cyber Attack
01 Oct 2025FireAnt.vn
FireAnt: OceanLotus Targets Stock Investors in FireAnt MetaKit Supply-Chain Hack

OceanLotus APT Executes Precision Supply-Chain Attack Targeting Vietnamese Stock Investors

783After Incident
CRITICAL-16
FIR1781188040
OceanLotus APT Executes Precision Supply-Chain Attack Targeting Vietnamese Stock Investors The advanced persistent threat (APT) group OceanLotus (APT32) conducted a sophisticated supply-chain compromise of FireAnt MetaKit, a widely used Vietnamese market-data component, deploying its SPECTRALVIPER backdoor to target stock investors. The operation, active from October 2025 to March 2026, exploited FireAnt’s unencrypted HTTP update mechanism, allowing attackers to serve malicious payloads via its legitimate update URL. The attack began with test iterations before escalating to heavily obfuscated downloaders, which used campaign-specific infrastructure, including the domain financemachinelearning[.]com, designed to blend with financial traffic. The downloader performed host reconnaissance, sent profiling data to a staging server, and deployed a side-loading chain involving DtlCrashCatch.dll (a SPECTRALVIPER loader) alongside a renamed, legitimately signed executable (IntelAudioService.exe). The malware then injected into OneDrive.Sync.Service.exe, beaconing to HTTPS command-and-control (C2) servers with encrypted host data embedded in HTTP cookie headers (using the zd_cs_pm= prefix). In parallel, OceanLotus maintained a long-running espionage campaign against a Vietnamese infrastructure and transport construction firm from mid-2024 to February 2026, using tailored SPECTRALVIPER variants side-loaded via legitimate executables (e.g., Toolbox.exe). Initial access likely exploited remote code execution (RCE) vulnerabilities in public SQL servers. A rare OPSEC lapse retained RTTI symbols in malware samples allowed researchers to reconstruct parts of SPECTRALVIPER’s internal class hierarchy, revealing its role as an HTTPS-based backdoor with orchestration capabilities. Compromised hosts communicated via named pipes, with designated "orchestrator" instances relaying commands to other infected systems. The attack’s timing and targeting align with Vietnam’s intensified anti-corruption and financial investigations, including the "Blazing Furnace" campaigns and regulatory scrutiny of bond misreporting in late 2025. This suggests the operation supported domestic surveillance or financial-crime probes rather than broad espionage or indiscriminate theft. OceanLotus, active since at least 2020 and resurgent with SPECTRALVIPER in 2023, has refined its tactics, favoring selective, domestically focused operations while retaining advanced tooling for stealthy supply-chain compromises. The group’s C2 infrastructure included domains like gatewayrvcenter[.]com and coachcybersecurity[.]com, hosted across providers such as OVH, Akamai, and Leaseweb, with no new malicious updates detected after March 9, 2026, indicating a possible cessation or disruption of the campaign.
INCIDENT DETAILS -
TYPE
Supply-chain attackEspionage
MOTIVATION
Domestic surveillanceFinancial-crime probes
IMPACT
Market-data components (FireAnt MetaKit)Infrastructure and transport construction firm systemsOperational Impact: Espionage and data exfiltration
DATA BREACH
Host profiling dataEncrypted host dataSensitivity Of Data: High (financial and operational intelligence)
SEPTEMBER 2025
799Before Incident
AUGUST 2025
799Before Incident
JULY 2025
799Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for FireAnt.vn ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in May 2026 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in April 2026 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in March 2026 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in February 2026 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in January 2026 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in December 2025 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in November 2025 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in October 2025 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in September 2025 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in August 2025 ?
?
What was FireAnt.vn's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on FireAnt.vn's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with FireAnt.vn ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view FireAnt.vn's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?