Extra credit: VietCredCare information stealer takes aim at Vietnamese businesses
ID: 2d530b78-b2dd-542e-b9bc-2a86d85209ca
STIX ID: report--2d530b78-b2dd-542e-b9bc-2a86d85209ca
Feed Name: Group-IB Blog
Group-IB uncovered VietCredCare, a Vietnam-focused .NET information stealer active since at least August 2022 that exfiltrates browser cookies and credentials to attacker-controlled Telegram bots. Offered as stealer‑as‑a‑service and advertised on social platforms, VietCredCare specifically filters Facebook credentials and checks Meta ad balances to prioritize takeover of business pages; it has compromised victims across 44 Vietnamese provinces including government agencies, universities, banks and major enterprises, uses persistence and evasion (packing, Windows Defender exclusions, AMSI disabling), and remains actively promoted and in use.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
