logo

BatShadow: Vietnamese Threat Actor Expands Its Digital Operations

ID: ce6efaf4-cb23-58a4-a06d-bea648a232b6

STIX ID: report--ce6efaf4-cb23-58a4-a06d-bea648a232b6

Feed Name: Aryaka

Threat Score
75/100

Date Published: 2025-10-07

Date Updated: 2026-04-27

Author: Aditya K Sood

...
...

Aryaka Threat Research Labs documents an active BatShadow campaign that targets job seekers and digital marketing professionals with ZIP-based lures (decoy PDFs plus malicious shortcuts/executables) that run hidden PowerShell to install a Go-based Vampire Bot. The malware performs host profiling, hides for persistence, captures periodic screenshots (compressed to WEBP), maintains an encrypted C2 loop for commands and payloads, and exfiltrates data; the research was responsibly shared with Proofpoint/ET to update detection rules.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.