Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

AAVE Price Prediction: $80 Is the Line in the Sand — Break It or Break Down

June 17, 2026

Trident Announces Termination of Deposit Agreement, Concurrent Changes to Share Capital and Direct Listing of Ordinary Shares

June 16, 2026

Onchain Data Locks In Satoshi’s 1.1M BTC Hoard — 3 Theories on Why It Never Moves

June 16, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Security

Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits

September 25, 2023No Comments2 Mins Read

An unidentified threat actor, reportedly originating from Vietnam, has been observed engaging in a ransomware campaign that commenced no later than June 4 and employing a variant of the Yashma ransomware, showcasing similarities to the infamous WannaCry ransomware.

According to a new advisory published by Cisco Talos on Monday, what sets this operation apart is the novel approach to delivering ransom notes. 

Instead of embedding ransom note strings within the malware binary, the attackers execute a batch file to retrieve the ransom note from their GitHub repository. This tactic provides a level of evasion against traditional endpoint security measures.

Talos’ analysis also indicated that the threat actor appears to target English-speaking countries, Bulgaria, China and Vietnam. The GitHub account linked to the attacker features ransom notes in languages associated with these regions. 

Furthermore, clues suggest a Vietnamese origin for the threat actor. The GitHub account’s name and email contact mimic a legitimate Vietnamese organization’s details, and the ransom note specifies contact hours in UTC+7, coinciding with Vietnam’s time zone.

The attackers also exhibited a heightened sensitivity towards Vietnamese victims, initiating their ransom note with an apologetic tone. This subtle linguistic variation might point to the attackers being Vietnamese.

The ransomware variant employed is a customized version of Yashma, with the actor compiling it on June 4, 2023. This .NET-based malware retains Yashma’s anti-recovery capability, erasing unencrypted files after encryption to impede recovery efforts.

Read more on Yashma: Emsisoft Releases Free Decryptor For AstraLocker and Yashma Ransomware

At present, the attackers demand ransom payments in Bitcoin to an identified wallet address and double the ransomware price if the victim fails to pay within three days. 

See also  MITRE Launches New Framework to Tackle Crypto Risks

However, no Bitcoin have been observed in the wallet yet, and the ransom amount remains unspecified, possibly indicating the campaign’s early stages.

Indicators of Compromise (IoC) associated with this threat can be found on Cisco Talos’ GitHub repository.

Source link

Mimics Operation ransomware Traits VietnameseOrigin WannaCry

Related Posts

India’s NHRC Raises Alarm Over Digital Arrest Scams

June 16, 2026

Rokarolla Trojan Combines Banking Fraud With Device Surveillance

June 16, 2026

Pyra to Cease Operations Following Drift Hack, Launches Fund Withdrawal Portal

June 16, 2026

Oklahoma Raises Alarm Over Fake Crypto Returns

June 16, 2026
Top Posts

Hacker breaches Nansen’s third-party vendor and exposes some of the crypto data company’s customer details

September 24, 2023

Report: Prediction Markets Polymarket and Kalshi Eye $20B Valuations as Investor Interest Builds

March 9, 2026

TRX Price Prediction: TRON Targets $0.35 Breakout Amid Overbought Signals

March 21, 2026

Type above and press Enter to search. Press Esc to cancel.