Vault Viper Exploits Online Gambling Websites Using Custom Browser to Install Malicious Program
ID: 77767936-ddb8-596c-81e8-263383f99423
STIX ID: report--77767936-ddb8-596c-81e8-263383f99423
Feed Name: cybersecurityNews.com
**Executive summary:** Infoblox and related reporting detail a criminal campaign in Southeast Asia distributing a modified Chromium browser (Universe Browser) via illegal gambling sites; the software routes traffic through actor-controlled servers, embeds RAT-like capabilities (keylogging, proxy/C2 management), uses anti-analysis techniques, and persists via startup registry and service components, with connections to the Vault Viper (Baoying Group/BBIN) ecosystem and observable C2 domains and file artifacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
