logo

Extra credit: VietCredCare information stealer takes aim at Vietnamese businesses

ID: 2d530b78-b2dd-542e-b9bc-2a86d85209ca

STIX ID: report--2d530b78-b2dd-542e-b9bc-2a86d85209ca

Feed Name: Group-IB Blog

Threat Score
75/100

Date Published: 2024-02-21

Date Updated: 2026-04-27

...
...

Group-IB uncovered VietCredCare, a Vietnam-focused .NET information stealer active since at least August 2022 that exfiltrates browser cookies and credentials to attacker-controlled Telegram bots. Offered as stealer‑as‑a‑service and advertised on social platforms, VietCredCare specifically filters Facebook credentials and checks Meta ad balances to prioritize takeover of business pages; it has compromised victims across 44 Vietnamese provinces including government agencies, universities, banks and major enterprises, uses persistence and evasion (packing, Windows Defender exclusions, AMSI disabling), and remains actively promoted and in use.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.