Vietnam.vn - Nền tảng quảng bá Việt Nam

Warning of 'Hanoi Thief' campaign attacking Vietnamese enterprises

A series of emails impersonating job applications, with attached files “Le Xuan Son CV.zip”, were sent to large and small businesses in Vietnam. This was a cover for a cyber attack campaign called Hanoi Thief, with the goal of infiltrating internal networks, taking over systems and stealing customer data and business secrets.

Báo Nhân dânBáo Nhân dân04/12/2025

Illustration photo.
Illustration photo.

Inside the compressed file is a shortcut file disguised as a job application, but actually contains the LOTUSHARVEST virus, which specializes in collecting saved password information, login cookies, and browsing history from Chrome, Edge browsers... and then sending it to the hacker's server.

According to Bkav experts, the shortcut file inside “Le Xuan Son CV.zip” is disguised under the PDF/PNG icon, making the recipient mistakenly think this is a normal CV file. With just one click, LOTUSHARVEST is immediately activated and begins the process of infiltrating the system.

The worrying point in this attack campaign is the sophisticated virus LOTUSHARVEST, which is capable of hiding deep and running on its own. LOTUSHARVEST takes advantage of the library loading mechanism to maintain long-term control and access sensitive accounts and data, beyond the protection of conventional security measures. Stolen data becomes the "key" for hackers to expand their penetration, deploy dangerous tools and turn businesses into multi-layered attacks or extortion targets in the next stages.

Mr. Nguyen Dinh Thuy, a malware analyst at Bkav, said: “All signs show that the Hanoi Thief campaign was meticulously planned, directly targeting Vietnamese businesses. Taking advantage of the recruitment department, which regularly receives applications from outside but is not fully equipped with cybersecurity awareness, hackers use fake files in the form of CVs or documents and can continuously transform into many different variations, making the risk of infection unpredictable.”

Bkav noted that there were Vietnamese businesses that were victims of this attack campaign. Due to the dangerous nature of LOTUSHARVEST and the Hanoi Thief campaign, users need to be extremely vigilant with documents received via email, because just one mistake can open the door for hackers.

Businesses and organizations need to regularly organize periodic training for employees, raise awareness and vigilance against online fraud tricks. Internal monitoring systems need to be strengthened, especially monitoring unusual libraries or suspicious files.

The default tools on the operating system only meet the basic protection needs, completely incapable of fighting against modern malware and viruses that can hide, persist for a long time and penetrate deeply into the system. Therefore, it is necessary to install an email monitoring system and use licensed anti-virus software to be protected professionally.

Source: https://nhandan.vn/canh-bao-chien-dich-hanoi-thief-tan-cong-mang-doanh-nghiep-viet-nam-post927978.html


Comment (0)

Please leave a comment to share your feelings!

Same category

Notre Dame Cathedral in Ho Chi Minh City is brightly lit to welcome Christmas 2025
Hanoi girls "dress up" beautifully for Christmas season
Brightened after the storm and flood, the Tet chrysanthemum village in Gia Lai hopes there will be no power outages to save the plants.
The capital of yellow apricot in the Central region suffered heavy losses after double natural disasters

Same author

Heritage

Figure

Enterprise

Dalat coffee shop sees 300% increase in customers because owner plays 'martial arts movie' role

News

Political System

Destination

Product