logo

Polygon Powered: Vietnamese Operator Deploys 16 Generations of LuaJIT Malware via GitHub

ID: 6ea3c23d-2e92-554c-977f-a482b4aad915

STIX ID: report--6ea3c23d-2e92-554c-977f-a482b4aad915

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-09

Date Updated: 2026-04-23

Author: Ddos

...
...

Researchers uncovered a year-long, large-scale campaign (active since Mar 2025) that uses 600+ malicious ZIP archives across dozens of GitHub accounts to distribute a multi-stage LuaJIT loader which resolves C2 via a Polygon smart contract and ultimately deploys the StealC information stealer; observed capabilities include credential harvesting, session hijacking, targeted reconnaissance, and optional module delivery, with infrastructure concentrated on bulletproof hosting and evidence pointing to a Vietnamese-speaking operator.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.