Vietnamese Cybercrime Group CoralRaider Nets Financial Data
ID: c1b0b88d-584c-543c-9250-4b76109220b2
STIX ID: report--c1b0b88d-584c-543c-9250-4b76109220b2
Feed Name: Dark Reading
CoralRaider, active since late 2023 and linked to Vietnam, conducts financially motivated account-stealing campaigns that use social engineering and a multistage Windows infection chain (LNK → HTA → VBScript → PowerShell → RotBot → XClient) to harvest social media credentials, browser and payment data, and screenshots; the group uses a Telegram bot for command-and-control and exfiltration, and researchers found evidence of operator errors exposing victim data and links to underground markets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
