logo

From Campus to C2: Tracking a Persistent Chinese Operation Against Vietnamese Universities

ID: 41fe6c7b-c440-5b65-b7fc-8f2517e1eda4

STIX ID: report--41fe6c7b-c440-5b65-b7fc-8f2517e1eda4

Feed Name: Ctrl-Alt-Int3l

Threat Score
90/100

Date Published: 2025-08-20

Date Updated: 2026-04-19

Author: Ctrl-Alt-Int3l

...
...

- This report describes an OSINT-driven analysis of an exposed open-directory that revealed a China-linked intrusion campaign compromising at least 25 Vietnamese universities: recovered Cobalt Strike and VShell servers, webshells (including .NET in-memory loaders), tunneling/RDP proxies, plaintext credentials, victim lists, exploitation logs (sqlmap, Metasploit), and numerous TTPs used for persistence, lateral movement, privilege escalation, and data collection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.