logo

Vietnam-Based Hackers Steal Financial Data Across Asia with Malware

ID: 8e2791d1-796d-548a-8d9e-b2a2d62d0be8

STIX ID: report--8e2791d1-796d-548a-8d9e-b2a2d62d0be8

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-04-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cisco Talos and other researchers attribute a multi-country, financially motivated campaign to a Vietnamese-origin cluster dubbed 'CoralRaider' that uses LNK→HTA→VBS→PowerShell chains with anti-analysis and UAC-bypass techniques to deploy RotBot (a customized Quasar RAT) which retrieves XClient stealer via Telegram; XClient steals browser cookies, credentials, financial details, Discord/Telegram data, and social media/business ad account information. The report also highlights Facebook malvertising operations that hijack legitimate pages and run sponsored ads to distribute information stealers (Rilide, Vidar, IceRAT, Nova Stealer), expanding the campaign's reach into Europe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.