216.73.216.36

Operation Hanoi Thief: Vietnam APT

· Published 28/11/2025 14:06 · Modified 21/12/2025 18:17

Export JSON

Essential information

Published
28/11/2025 14:06
Modified
21/12/2025 18:17
Tags
2025-11-28 browser credentials dll sideloading information stealer it-professionals lotusharvest recruiters spear-phishing vietnam
Related entities
4 observables, 12 techniques (mitre), 1 malware, 3 others

Description

A campaign dubbed 'Operation Hanoi Thief' is targeting Vietnamese IT professionals and recruitment teams. The attack uses a malicious ZIP file containing a fake resume and an LNK file. The LNK file executes a pseudo-polyglot payload, which deploys a C++ DLL implant called through . This implant functions as an , harvesting and history before exfiltrating data to attacker-controlled servers. The campaign employs anti-analysis techniques and abuses trusted Windows tools. While similarities with previous Chinese-origin campaigns exist, definitive state sponsorship attribution remains inconclusive. The operation primarily affects the Information Technology and Recruitment sectors in .

External references