Common Information
Type Value
Value
CoralRaider
Category Actor
Type Threat-Actor
Misp Type Cluster
Description CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They use the RotBot loader family and XClient stealer to steal victim information, with hardcoded Vietnamese words in their payloads. CoralRaider operates from Hanoi, Vietnam, and uses a Telegram bot as a C2 channel for their malicious campaigns. Their activities include system reconnaissance, data exfiltration, and targeting victims in multiple countries in the region.
Details Published Attributes CTI Title
Details Website 2024-11-17 0 🚨 Vietnamese Hackers Unleash PXA Stealer: Targeting Sensitive Data Across Europe and Asia 🌍🔓
Details Website 2024-11-14 35 New PXA Stealer targets government and education sectors for sensitive information
Details Website 2024-11-14 34 New PXA Stealer targets government and education sectors for sensitive information
Details Website 2024-09-16 2 Emmenhtal
Details Website 2024-09-06 0 The 2024 Threat Landscape State of Play
Details Website 2024-09-06 0 The 2024 Threat Landscape State of Play
Details Website 2024-08-15 22 5 Malware Variants You Should Know - ReliaQuest