Threats Tagged 'it-professionals'
View all threats tagged with 'it-professionals'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'it-professionals'
Click on any threat for detailed analysis and mitigation recommendations
Operation Hanoi Thief is a spear-phishing campaign targeting Vietnamese IT professionals and recruitment teams. It uses malicious ZIP files containing fake resumes and LNK files that execute a pseudo-polyglot payload. This payload deploys a C++ DLL implant named LOTUSHARVEST via DLL sideloading, which steals browser credentials and history. The stolen data is exfiltrated to attacker-controlled servers. The campaign uses anti-analysis techniques and abuses trusted Windows tools to evade detection. While it shares similarities with Chinese-origin campaigns, state sponsorship is not confirmed. The attack primarily affects Vietnam's IT and recruitment sectors, with no known exploits in the wild beyond spear-phishing. The campaign poses a medium severity threat due to its targeted nature and credential theft capabilities. European organizations are not directly targeted but could be at risk if similar tactics spread. Mitigation requires focused user training, monitoring for DLL sideloading, and blocking known indicators of compromise. Join the discussion | AlienVault OTX General | 11/28/2025, 14:06:46 UTC Added: 11/28/2025, 18:53:55 UTC |
Showing 1 to 1 of 1 result