Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

TON Price Prediction: $1.50 Target as Technical Indicators Signal Potential 13% Rally

May 2, 2026

The Cheap Foreign Labor Regime Blocking Agricultural Intelligence

May 2, 2026

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Security

Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits

September 25, 2023No Comments2 Mins Read

An unidentified threat actor, reportedly originating from Vietnam, has been observed engaging in a ransomware campaign that commenced no later than June 4 and employing a variant of the Yashma ransomware, showcasing similarities to the infamous WannaCry ransomware.

According to a new advisory published by Cisco Talos on Monday, what sets this operation apart is the novel approach to delivering ransom notes. 

Instead of embedding ransom note strings within the malware binary, the attackers execute a batch file to retrieve the ransom note from their GitHub repository. This tactic provides a level of evasion against traditional endpoint security measures.

Talos’ analysis also indicated that the threat actor appears to target English-speaking countries, Bulgaria, China and Vietnam. The GitHub account linked to the attacker features ransom notes in languages associated with these regions. 

Furthermore, clues suggest a Vietnamese origin for the threat actor. The GitHub account’s name and email contact mimic a legitimate Vietnamese organization’s details, and the ransom note specifies contact hours in UTC+7, coinciding with Vietnam’s time zone.

The attackers also exhibited a heightened sensitivity towards Vietnamese victims, initiating their ransom note with an apologetic tone. This subtle linguistic variation might point to the attackers being Vietnamese.

The ransomware variant employed is a customized version of Yashma, with the actor compiling it on June 4, 2023. This .NET-based malware retains Yashma’s anti-recovery capability, erasing unencrypted files after encryption to impede recovery efforts.

Read more on Yashma: Emsisoft Releases Free Decryptor For AstraLocker and Yashma Ransomware

At present, the attackers demand ransom payments in Bitcoin to an identified wallet address and double the ransomware price if the victim fails to pay within three days. 

See also  Operation First Light Seizes $257m in Global Scam Bust

However, no Bitcoin have been observed in the wallet yet, and the ransom amount remains unspecified, possibly indicating the campaign’s early stages.

Indicators of Compromise (IoC) associated with this threat can be found on Cisco Talos’ GitHub repository.

Source link

Mimics Operation ransomware Traits VietnameseOrigin WannaCry

Related Posts

Meteora reports $1.5 million OTC scam loss in Q1 MET report

May 2, 2026

Crypto hack losses top $630M in April, highest since February 2025

May 2, 2026

US seized $500M in Iranian crypto assets, Treasury secretary says

May 2, 2026

Wasabi Protocol drained for $4.5 million in apparent admin key compromise

May 2, 2026
Top Posts

Bitcoin’s $100,000 climb hindered by US financial turbulence

February 13, 2026

Google paves way for AI-produced content with new policy

September 27, 2023

Crypto Biz: BlockFi emerges from bankruptcy, Worldcoin halts USDC payments and more

October 28, 2023

Type above and press Enter to search. Press Esc to cancel.