Vietnam-Based Hackers Steal Financial Data Across Asia with Malware
ID: 8e2791d1-796d-548a-8d9e-b2a2d62d0be8
STIX ID: report--8e2791d1-796d-548a-8d9e-b2a2d62d0be8
Feed Name: The Hacker News
Cisco Talos and other researchers attribute a multi-country, financially motivated campaign to a Vietnamese-origin cluster dubbed 'CoralRaider' that uses LNK→HTA→VBS→PowerShell chains with anti-analysis and UAC-bypass techniques to deploy RotBot (a customized Quasar RAT) which retrieves XClient stealer via Telegram; XClient steals browser cookies, credentials, financial details, Discord/Telegram data, and social media/business ad account information. The report also highlights Facebook malvertising operations that hijack legitimate pages and run sponsored ads to distribute information stealers (Rilide, Vidar, IceRAT, Nova Stealer), expanding the campaign's reach into Europe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
