← Back to Pulse Feed
PULSE DETAIL
A sophisticated CHM-based malware campaign has been identified targeting Vietnamese victims through a trojanized CV document. The infection chain utilizes a compiled HTML file that deploys a multi-stage payload delivery mechanism involving Python interpreters, C++ DLLs, and layered XOR encryption. The malware establishes persistence through Shell hijacking and scheduled tasks, ultimately delivering a weaponized version of Rebex.Common.dll functioning as a Telegram-based remote access trojan. The RAT communicates via Telegram bot API, supporting commands for file download, token swapping, and arbitrary command execution. The infection demonstrates characteristics typical of targeted state-sponsored activity rather than opportunistic cybercrime, employing techniques historically associated with advanced threat actors operating in the Southeast Asian region.
MITRE ATT&CK & Malware Families
Indicators of Compromise (5 / 15 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| FileHash-MD5 | 4e9e70c2a8002ce4a70ab43ae80c2a25 | — | 2026-04-29 | |
| FileHash-MD5 | 783698157743014acd2df3e721c1ae4e | — | 2026-04-29 | |
| FileHash-MD5 | b30cfa26e5dbee1665944a7a94b1a07d | — | 2026-04-29 | |
| FileHash-MD5 | b3bf26bfbf7aec43379523bd18b1ec16 | — | 2026-04-29 | |
| FileHash-MD5 | ca3401817dd1e29ca3f3212e38ad39cf | — | 2026-04-29 |
References (1)