/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Investigation details how a hacking group called OceanLotus has been spying on Vietnamese opposition members and dissidents for years, including in Germany

BR24 : Tweets: @campuscodi , @snlyngaas , @sienaanstis , and @hatr Tweets: Catalin Cimpanu / @campuscodi : This was, by far, the best cybersecurity article published last week. It's a long read but worth it. This is also a visual experience, so don't use text-to-speech readers. View it in your browsers, desktop preferably. https://twitter.com/... Sean Lyngaas / @snlyngaas : Adding my voice to the chorus of people praising this brilliant story from @hatr et al. The best infosec journalism is about humans, their rights, their quest to protect themselves from malicious forces. This story skillfully illuminates that struggle: https://web.br.de/... Siena Anstis / @sienaanstis : Absolutely genius use of graphics & fascinating reporting shining a light on digital threats faced by dissidents in Germany and the failure of authorities to respond. ⁦⁦@RonDeibert⁩ ⁦@SharlyChan⁩ ⁦@jsrailton⁩ https://web.br.de/... Hakan / @hatr : Here is the english version of our investigation on #APT32/#OceanLotus, a group that is relentlessly targeting civil society. We're telling the stories of the people affected, of threat intel analysts tracking them and one (potential) mistake they've made https://web.br.de/...

BR24

Context & Ripple Effects

German audiences already know the shape of state-backed intrusion from the years-long Winnti campaign against German corporations uncovered by Bayerischer Rundfunk in 2019 — but that story was about companies as targets. The new BR24 investigation moves the target to people: OceanLotus (APT32) spying on Vietnamese opposition members and dissidents, including on German soil.

The reporting lands amid a broader documentation effort by security journalists and researchers — Catalin Cimpanu, Sean Lyngaas, and Siena Anstis among those amplifying it — into how spy work is increasingly outsourced and commercialized, from the hacker-for-hire group RocketHack compromising thousands of email and Telegram accounts to APT40's use of front companies. The relationships here note a sharp detail: German authorities failed to respond to the digital threats against the dissidents OceanLotus targeted.

First-order effects

  • Vietnamese dissidents and opposition members in Germany remain exposed today, because the investigation documents that German authorities did not act on the digital threats against them — protection currently depends on the targets themselves and the researchers documenting the attacks.

Second-order effects

  • Berlin faces an awkward position it helped create: it has opposed EU plans to ban Chinese suppliers like Huawei from telecom networks under new cybersecurity rules, while its own territory hosts state-linked spying on political exiles — giving domestic critics and EU partners leverage to question whether Germany's threat model covers people, not just firms.

Third-order effects

  • If the pattern holds across the documented cases — Winnti hitting corporations, RocketHack selling intrusion to whoever pays, OceanLotus tracking dissidents abroad — the structural shift is toward espionage-as-a-service aimed at individuals, forcing democracies to decide whether diaspora protection becomes a formal security obligation rather than an ad hoc gap.

The trend: State-linked hacking is expanding from corporate espionage toward surveillance of exiled dissidents and civil society, with host governments like Germany slower to defend people than companies.

Discussion

  • @campuscodi Catalin Cimpanu on x
    This was, by far, the best cybersecurity article published last week. It's a long read but worth it. This is also a visual experience, so don't use text-to-speech readers. View it in your browsers, desktop preferably. https://twitter.com/...
  • @snlyngaas Sean Lyngaas on x
    Adding my voice to the chorus of people praising this brilliant story from @hatr et al. The best infosec journalism is about humans, their rights, their quest to protect themselves from malicious forces. This story skillfully illuminates that struggle: https://web.br.de/...
  • @sienaanstis Siena Anstis on x
    Absolutely genius use of graphics & fascinating reporting shining a light on digital threats faced by dissidents in Germany and the failure of authorities to respond. ⁦⁦@RonDeibert⁩ ⁦@SharlyChan⁩ ⁦@jsrailton⁩ https://web.br.de/...
  • @hatr Hakan on x
    Here is the english version of our investigation on #APT32/#OceanLotus, a group that is relentlessly targeting civil society. We're telling the stories of the people affected, of threat intel analysts tracking them and one (potential) mistake they've made https://web.br.de/...