Skip to main content

Threats Affecting Vietnam

View all threats affecting or targeting Vietnam. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:VietnamVietnam

Threats Affecting Vietnam

Click on any threat for detailed analysis and mitigation recommendations

Cisco Talos identified a Chinese-speaking cybercrime group, UAT-10147, conducting large-scale attacks against Windows and Linux web servers globally. The group exploits publicly disclosed vulnerabilities to gain initial access and integrates AI-driven tools to automate exploitation, reconnaissance, payload generation, validation, and persistence. Targets include organizations in government, education, media, technology, and gaming sectors across Brazil, Bolivia, China, Canada, and Vietnam. The actor deploys malware for SEO fraud and data theft, using multiple open-source offensive frameworks and privilege escalation tools. The infection chains involve multi-stage scripts that evade detection and establish persistence via backdoors and rogue accounts. Talos assesses this as a financially motivated campaign leveraging semi-autonomous AI orchestration to scale complex intrusions efficiently.

Join the discussion

OkoBot is a malicious framework delivering over 20 payloads aimed at stealing cryptocurrency wallet seed phrases, credentials, and sensitive data. It spreads via ClickFix attacks and trojanized GitHub repositories. The infection chain involves multiple stages, starting with a PowerShell script that installs an SSH bot to collect system info and disable Windows Defender notifications. Key modules include browser injectors, fake seed phrase prompts targeting hardware wallets, keyloggers, and spyware that records video and keystrokes. The campaign has been active since early 2025 with a global reach, primarily impacting Brazil, Vietnam, Canada, Mexico, and Turkey. Indicators of compromise and detailed telemetry are available from Kaspersky. No official patch or remediation is noted.

Join the discussion
0

In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

Join the discussion

An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. [...]

Join the discussion

A malware-as-a-service campaign named Weedhack targets Minecraft users by distributing malicious Java JAR files via SEO poisoning and YouTube videos. The malware steals credentials, system information, and can remotely control infected systems. It is notable for its ease of access, free tier, and appeal to younger users, with infections primarily in the U. S.and several other countries. Additionally, a large CountLoader campaign spreads cryptocurrency clipper malware via cracked software, and a separate campaign distributes cryptocurrency miners through pirated content sites. These campaigns leverage sophisticated persistence and evasion techniques and have been active since early 2026.

Join the discussion

A sophisticated CHM-based malware campaign has been identified targeting Vietnamese victims through a trojanized CV document. The infection chain utilizes a compiled HTML file that deploys a multi-stage payload delivery mechanism involving Python interpreters, C++ DLLs, and layered XOR encryption. The malware establishes persistence through Shell hijacking and scheduled tasks, ultimately delivering a weaponized version of Rebex.Common.dll functioning as a Telegram-based remote access trojan. The RAT communicates via Telegram bot API, supporting commands for file download, token swapping, and arbitrary command execution. The infection demonstrates characteristics typical of targeted state-sponsored activity rather than opportunistic cybercrime, employing techniques historically associated with advanced threat actors operating in the Southeast Asian region.

Join the discussion
CVE-2026-30643: n/aCVE-2026-30643
0

An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.

Join the discussion
CVE-2026-30573: n/aCVE-2026-30573
0

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0. The vulnerability is located in the add-sales.php file. The application fails to validate the "txtprice" and "txttotalcost" parameters, allowing attackers to submit negative values for sales transactions. This leads to incorrect financial calculations, corruption of sales reports, and potential financial loss.

Join the discussion

Key Points Introduction At the beginning of 2026, Check Point Research observed a series of targeted attacks against government entities in Southeast Asia carried out via a legitimate TrueConf software installed in the targets’ environment. The investigation led to the discovery of a zero-day vulnerability in the TrueConf client, tracked as CVE-2026-3502 with a CVSS score of 7.8. […] The post Operation TrueChaos: 0-Day Exploitation Against Southeast Asian Government Targets appeared first on Check Point Research .

Join the discussion
CVE-2026-30564: n/aCVE-2026-30564
0

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Sales and Inventory System 1.0. The vulnerability is located in the view_payments.php file via the "limit" parameter. The application fails to sanitize the input, allowing remote attackers to inject arbitrary web script or HTML via a crafted URL.

Join the discussion

Showing 1 to 10 of 910 results

Filters:Country: Vietnam
Page 1 of 91
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses