Threats Tagged 'vietnam'
View all threats tagged with 'vietnam'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'vietnam'
Click on any threat for detailed analysis and mitigation recommendations
A Vietnamese threat actor is employing AI to develop code for an ongoing phishing campaign delivering PureRAT malware and other payloads. The attacks begin with phishing emails disguised as job opportunities, potentially targeting work computers. The attacker's use of AI is evidenced by detailed comments and numbered steps in scripts, as well as instructions in debug messages. The attack chain involves malicious archives, sideloaded DLLs, and batch scripts likely authored using AI. The attacker appears to be continually refining their methods and may be selling access to compromised organizations. This case demonstrates how AI can lower the barrier to entry for less skilled attackers, helping them write code and build attack toolkits. Join the discussion | AlienVault OTX General | 01/28/2026, 17:20:03 UTC Added: 01/28/2026, 18:50:56 UTC |
Operation Hanoi Thief is a spear-phishing campaign targeting Vietnamese IT professionals and recruitment teams. It uses malicious ZIP files containing fake resumes and LNK files that execute a pseudo-polyglot payload. This payload deploys a C++ DLL implant named LOTUSHARVEST via DLL sideloading, which steals browser credentials and history. The stolen data is exfiltrated to attacker-controlled servers. The campaign uses anti-analysis techniques and abuses trusted Windows tools to evade detection. While it shares similarities with Chinese-origin campaigns, state sponsorship is not confirmed. The attack primarily affects Vietnam's IT and recruitment sectors, with no known exploits in the wild beyond spear-phishing. The campaign poses a medium severity threat due to its targeted nature and credential theft capabilities. European organizations are not directly targeted but could be at risk if similar tactics spread. Mitigation requires focused user training, monitoring for DLL sideloading, and blocking known indicators of compromise. Join the discussion | AlienVault OTX General | 11/28/2025, 14:06:46 UTC Added: 11/28/2025, 18:53:55 UTC |
A Chinese-speaking threat actor group, tracked as CL-UNK-1037, has been conducting a large-scale SEO poisoning campaign called Operation Rewrite. The attackers use a malicious IIS module named BadIIS to intercept and alter web traffic on compromised servers, manipulating search engine results to redirect users to malicious sites. The campaign primarily targets East and Southeast Asia, with a focus on Vietnam. The attackers employ various tools including native IIS modules, ASP.NET handlers, and PHP scripts. The operation shows links to previously known threat groups like Group 9 and possibly DragonRank. The campaign demonstrates sophisticated techniques for search result manipulation and traffic redirection, posing significant risks to unsuspecting internet users. Join the discussion | AlienVault OTX General | 09/25/2025, 09:20:57 UTC Added: 09/25/2025, 14:18:55 UTC |
A sophisticated Android banking trojan named RedHook has been discovered targeting Vietnamese users through spoofed government and financial websites. The malware uses WebSocket to communicate with its command-and-control server and supports over 30 remote commands, enabling complete control over compromised devices. RedHook combines phishing, RAT, and keylogging capabilities to exfiltrate credentials and conduct fraud. It abuses Android's MediaProjection API for screen capture and sends data to a live C2 server. The malware's low antivirus detection rate makes it a stealthy and active threat. Code artifacts suggest development by a Chinese-speaking threat actor or group. An exposed AWS S3 bucket revealed operational data dating back to November 2024, indicating a shift from previous scam campaigns to this advanced banking trojan. Join the discussion | AlienVault OTX General | 07/31/2025, 19:23:46 UTC Added: 07/31/2025, 19:32:44 UTC |
A hacking group with alleged ties to Vietnam has been exploiting social media ads promoting AI video generators to distribute malware since mid-2024. The campaign, discovered by Mandiant, uses fake websites mimicking legitimate AI tools to deploy payloads including Python-based infostealers and backdoors. The group, tracked as UNC6032, has reached millions of users through Facebook and LinkedIn ads, primarily targeting EU countries and the US. The malware distributed includes STARKVEIL, XWORM, FROSTRIFT, and GRIMPULL, designed for information theft and capable of downloading additional plugins. The attackers employ a multi-payload mechanism for resilience against detection. Users are advised to exercise caution when engaging with AI tools and verify website legitimacy. Join the discussion | AlienVault OTX General | 05/28/2025, 17:57:41 UTC Added: 05/28/2025, 20:43:52 UTC |
Showing 1 to 5 of 5 results