2. 01 Dark Web Threats
02 Ransomware Threats
03 Top Target Industry
04 Stealer Logs
05 Phishing Threats
06 Threat Actors
Agenda
2022/04/18 - 2023/04/18
3. Dark Web Threats
- 1 -
149 Dark Web
Threats
in last one year.
Most Category are Selling and Sharing
SOCRadar CTIA team has monitored the dark
web to nd trends and essential links.
Throughout the this year, Vietnam enterprises
were bombarded with cyber attacks. Various
threat actors have tried to sell and
sometimes share the fruits of these
successful cyberattacks on dark web hacker
forums.
97 Dark web Threat Actors
nkbahim
Milad
toxcorrect
aassszzxvcvcvcxc
Pa8sw0rd
4. 2023-03-08
Database of Government of
Vietnam is on Sale
In a hacker forum monitored by SOCRadar,
a new alleged database sale is detected for
Government of Vietnam. How is it going?
I'm selling a DB from Vietnam, it's a govt d
atabase. Format is fullname || IDNumber ||
IDIssuedate || IDIssueplace || nationa...
2023-03-07
Sensitive Data of Government of
Vietnam are Leaked
In a hacker forum monitored by SOCRadar,
a new alleged sensitive data leak are detec
ted for Government of Vietnam.Hello To All
Underground Users kekhaigia.danang.gov.
vn Government of Vietnam [ Backup Files ]
Download Backup :https:/*****************
*G...
Dark Web Threats
- 2 -
5. 2023-02-27
Database of Shopee
Vietnam is ...
In a hacker forum monitored by SO
CRadar, a new alleged database sal
e is detected for Shopee Vietnam .h
ello, today i am selling shopee data
base in vietnam with more than 24+
million orders. someone scraped it
and I got it in May 2022Price 1000$
BTC or...
2023-02-26
Customer Database of
Vietnam C...
In a hacker forum monitored by SO
CRadar, a new alleged database lea
k is detected for Vietnam Central Or
ganizing Committee.Link:https://m
ega.nz/ le/FlhG1Lg***************
******************In addition, we sel
l the authority of the Malay Ministry
of Fo...
2023-02-23
Data of Many Vietnamese
Financ...
In a hacker forum monitored by SO
CRadar, a new alleged data sale is d
etected for many nance companie
s operating in Vietnam.I'm seeking
a con dential database for Vietnam
that includes header information su
ch as ID number, name, address, an
d mobile...
Dark Web Threats
- 3 -
6. Ransomware Threats
- 4 -
3 ransomware
attacks
in Vietnam.
Ransomware attacks are among the most critical
cyber attacks an organization can experience. The
results can be destructive for an organization and
lead to massive data loss and leaks of the victim
company's sensitive data.
3 Ransomware Gangs
Everest
Midas
Suncrypts
8. Ransomware Threats
The New Ransomware Victim of Everest: VTVCAB
In the Everest ransomware group website monitored by SOCRadar, a new ransomware victim was
allegedly announced as Collegiate Sports Medicine.VTVCABThe servers of the telecommunications
center VTVCAB were blocked, as well as tens of terabytes of data,...
The New Ransomware Victim of Midas: NetCompany
In the Midas ransomware group website monitored by SOCRadar, a new ransomware victim
allegedly announced as NetCompany.NetCompanyCompany: NetCompanyAddress: -Website: -
Phone: -Next update: 1 Days 21 : 51 : 43-
The New Ransomware Victim of Suncrypts: FitFlop
In the Suncrypts ransomware group website monitored by SOCRadar, a new ransomware victim
allegedly announced as FitFlop Ltd.FitFlop Ltd.https:// t op.com/InfoLock date Phone Address Full
dump NoDDOS NoContentA small sample of data.We will be publis...
- 6 -
9. Top Target Industry
- 7 -
64 Different industries targeted in Vietnam
Dark Web Industry Threats Ransomware Industry Threats
10. 1565 phishing domains
detected in Vietnam
Phishing Threats
Brand impersonation takes place when a threat actor creates a social account pretending to be your
brand. SOCRadar can spot fraudulent and fake domain. Also can spot fake social accounts by
monitoring well-known social media platforms so that you can quickly take action to stop possible
phishing scams.
- 8 -
Phishing Domain Sector Register Date
gcosoftware.vn National Security... 2023-03-09
helpid68303423.com 2023-03-09
userprotection33413245.cl... 2023-03-08
maycanbangionz755.com 2023-03-08
maycanbangionz755.com 2023-03-08
maycanbangionz755.com 2023-03-08
maycanbangionz755.com 2023-03-08
2023-03-08
2023-03-07
+1556 Phishing Threats
11. Related malware families
AZORult Trojan
The AZORult malware was rst discovered in 2016 to be an
information stealer that steals browsing history, cookies,
ID/passwords, cryptocurrency information and more. It can
also act as a downloader of other malware. It was sold on
Russian underground forums to collect various types of
sensitive information from an infected computer.
Raccoon Infostealer
Raccoon emerged as Malware as a Service (MaaS) in April
2019. The malware is capable of stealing login credentials,
credit card information, cryptocurrency wallets, and browser
information. Raccoon has basic infostealer functions but an
aggressive marketing campaign and overall good user
experience proved enough to make up for its lack of
additional features.
Stealer Logs
As one of the emerging underground market, threat actors are selling stolen identities from malware bot-infected devices frequently
advertised as stealer logs. These bots-for-sale marketplaces affect not just users whose credentials and digital identities are stolen,
but also the organizations that users are working for. SOCRadar provides you the continuous visibility to detect this evolving threat.
- 9 -
1515Stealer Logs in
Vietnam
Entity Type Date
https://authgop.garena.com/oau... url 2023-03-10
https://free- re.vn/ url 2023-03-10
https://www.fshare.vn/site/sig... url 2023-03-10
https://login.live.com/oauth20... url 2023-03-10
https://accounts.google.com/ url 2023-03-10
https://app.gostudio.co/signup... url 2023-03-10
+1507 Stealer Logs
12. Threat Actors
10 threat actors found in Vietnam
- 10 -
Group Name Aliases Sectors
ToddyCat Websiic Public Administration National Security&International
Affairs
APT32 APT 32 , OceanLotus , SeaLotus G0050 ... Manufacturing , Public Administration Publishing Services ...
Aoqin Dragon UNC94 Educational Services , Public Administration Telecommunications
Lotus Blossom Esile , G0030 , DRAGONFISH LOTUS PANDA ... Manufacturing , HealthCare & Social Assistance Public
Administration ...
Naikon Override Panda , DRAGONFISH , Cycldek G0019 ... Manufacturing , Public Administration Energy & Utilities ...
+1 Threat Actors