PULSE NAME
Rebex-based Telegram RAT Targeting Vietnam
WHITE AlienVault 2026-04-29 Modified: 2026-04-29
15
IOCs
MEDIUM VOLUME
A sophisticated CHM-based malware campaign has been identified targeting Vietnamese victims through a trojanized CV document. The infection chain utilizes a compiled HTML file that deploys a multi-stage payload delivery mechanism involving Python interpreters, C++ DLLs, and layered XOR encryption. The malware establishes persistence through Shell hijacking and scheduled tasks, ultimately delivering a weaponized version of Rebex.Common.dll functioning as a Telegram-based remote access trojan. The RAT communicates via Telegram bot API, supporting commands for file download, token swapping, and arbitrary command execution. The infection demonstrates characteristics typical of targeted state-sponsored activity rather than opportunistic cybercrime, employing techniques historically associated with advanced threat actors operating in the Southeast Asian region.
Indicators of Compromise (5 / 15 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 4e9e70c2a8002ce4a70ab43ae80c2a25 2026-04-29
FileHash-MD5 783698157743014acd2df3e721c1ae4e 2026-04-29
FileHash-MD5 b30cfa26e5dbee1665944a7a94b1a07d 2026-04-29
FileHash-MD5 b3bf26bfbf7aec43379523bd18b1ec16 2026-04-29
FileHash-MD5 ca3401817dd1e29ca3f3212e38ad39cf 2026-04-29