Vietnam.vn - Nền tảng quảng bá Việt Nam

Warning of Hanoi Thief cyber attack campaign targeting Vietnamese businesses

The cyber attack campaign named Hanoi Thief aims to infiltrate the internal network, take over the system and steal customer data and business secrets.

Báo Tuổi TrẻBáo Tuổi Trẻ04/12/2025

Cảnh báo chiến dịch tấn công mạng Hanoi Thief nhắm vào doanh nghiệp Việt Nam - Ảnh 1.

Hanoi Thief cyber attack campaign targets Vietnamese businesses - Photo: THU HANG

On December 4, Bkav Cyber ​​Security Company warned that a Vietnamese enterprise had become a victim of a cyber attack campaign called Hanoi Thief from abroad that directly attacked Vietnamese enterprises.

Accordingly, a series of emails with fake job applications, attached with the file "Le Xuan Son CV.zip", were sent to large and small businesses in Vietnam.

Inside the compressed file is a shortcut file disguised as a job application, but actually contains the LotusHarvest virus, which collects saved password information, login cookies, and browsing history from Chrome, Edge browsers, etc. and sends it to the hacker's server.

According to Bkav experts, the shortcut file inside “Le Xuan Son CV.zip” is disguised under the PDF/PNG icon, making the recipient mistakenly think this is a normal CV file. With just one click, LotusHarvest is immediately activated and begins the process of infiltrating the system.

The worrying point in the attack campaign is that this sophisticated virus has the ability to hide deep and run on its own. LotusHarvest takes advantage of the library loading mechanism to maintain long-term control and access sensitive accounts and data, beyond the protection of conventional security measures.

Stolen data becomes the “key” for hackers to expand their penetration, deploy dangerous tools and turn businesses into targets for multi-layered attacks or extortion in the next stages.

Mr. Nguyen Dinh Thuy, a malware analyst at Bkav, said: “All signs show that the Hanoi Thief campaign was meticulously planned, directly targeting Vietnamese businesses.

Taking advantage of the recruitment department, which regularly receives applications from outside but is not fully equipped with cybersecurity awareness, hackers use fake files in the form of CVs or documents and can continuously transform into many different variations, making the risk of infection unpredictable.

Beware of documents received via email

Due to the dangerous nature of LotusHarvest and the Hanoi Thief campaign, users need to be extremely vigilant with documents received via email, as even a single mistake can “open the door” for hackers.

Businesses and organizations need to regularly organize periodic training for employees, raise awareness and vigilance against online fraud tricks. Internal monitoring systems need to be strengthened, especially monitoring unusual libraries or suspicious files.

The default tools on the operating system only meet the basic protection needs, completely incapable of fighting against modern malware and viruses that can hide, persist for a long time and penetrate deeply into the system. Therefore, it is necessary to install an email monitoring system and use licensed anti-virus software to be protected professionally.

VIRTUE

Source: https://tuoitre.vn/canh-bao-chien-dich-tan-cong-mang-hanoi-thief-nham-vao-doanh-nghiep-viet-nam-2025120413552988.htm


Comment (0)

Please leave a comment to share your feelings!

Same tag

Same category

Notre Dame Cathedral in Ho Chi Minh City is brightly lit to welcome Christmas 2025
Hanoi girls "dress up" beautifully for Christmas season
Brightened after the storm and flood, the Tet chrysanthemum village in Gia Lai hopes there will be no power outages to save the plants.
The capital of yellow apricot in the Central region suffered heavy losses after double natural disasters

Same author

Heritage

Figure

Enterprise

Dalat coffee shop sees 300% increase in customers because owner plays 'martial arts movie' role

News

Political System

Destination

Product