logo

Vietnamese Cybercrime Group CoralRaider Nets Financial Data

ID: c1b0b88d-584c-543c-9250-4b76109220b2

STIX ID: report--c1b0b88d-584c-543c-9250-4b76109220b2

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-04-09

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

CoralRaider, active since late 2023 and linked to Vietnam, conducts financially motivated account-stealing campaigns that use social engineering and a multistage Windows infection chain (LNK → HTA → VBScript → PowerShell → RotBot → XClient) to harvest social media credentials, browser and payment data, and screenshots; the group uses a Telegram bot for command-and-control and exfiltration, and researchers found evidence of operator errors exposing victim data and links to underground markets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.