logo

Vietnamese Threat Actor's Strategy On Digital Marketers

ID: 0ca4b64a-7e62-5b22-bfcb-e1a9bb811db7

STIX ID: report--0ca4b64a-7e62-5b22-bfcb-e1a9bb811db7

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2026-03-18

Date Updated: 2026-07-17

...
...

Executive Summary: Cyble Research and Intelligence Labs (CRIL) uncovered a targeted, multi-stage malware campaign delivering a modified Quasar RAT via a malicious LNK/Powershell chain and AES-encrypted payloads; the campaign uses extensive sandbox/VM and debugger detection, privilege escalation (PowerShell/CMSTP), persistence, and defense evasion, is attributed to a Vietnamese threat actor targeting Meta Ads/digital marketing professionals, and includes IOCs and MITRE ATT&CK mappings for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.