Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Flowra Adds Compliance Rules to Solana

August 4, 2026

Kraken delisted tokens face liquidation, users could get $0

August 4, 2026

ONDO loses key support as team dumps 20M tokens: Can bulls hold on?

August 4, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Security and Privacy

Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits

August 8, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

An unidentified threat actor, reportedly originating from Vietnam, has been observed engaging in a ransomware campaign that commenced no later than June 4 and employing a variant of the Yashma ransomware, showcasing similarities to the infamous WannaCry ransomware.

According to a new advisory published by Cisco Talos on Monday, what sets this operation apart is the novel approach to delivering ransom notes. 

Instead of embedding ransom note strings within the malware binary, the attackers execute a batch file to retrieve the ransom note from their GitHub repository. This tactic provides a level of evasion against traditional endpoint security measures.

Talos’ analysis also indicated that the threat actor appears to target English-speaking countries, Bulgaria, China and Vietnam. The GitHub account linked to the attacker features ransom notes in languages associated with these regions. 

Furthermore, clues suggest a Vietnamese origin for the threat actor. The GitHub account’s name and email contact mimic a legitimate Vietnamese organization’s details, and the ransom note specifies contact hours in UTC+7, coinciding with Vietnam’s time zone.

The attackers also exhibited a heightened sensitivity towards Vietnamese victims, initiating their ransom note with an apologetic tone. This subtle linguistic variation might point to the attackers being Vietnamese.

The ransomware variant employed is a customized version of Yashma, with the actor compiling it on June 4, 2023. This .NET-based malware retains Yashma’s anti-recovery capability, erasing unencrypted files after encryption to impede recovery efforts.

Read more on Yashma: Emsisoft Releases Free Decryptor For AstraLocker and Yashma Ransomware

At present, the attackers demand ransom payments in Bitcoin to an identified wallet address and double the ransomware price if the victim fails to pay within three days. 

See also  Ransomware and theft drive over $2 billion in illicit crypto activity in 2024 – Chainalysis

However, no Bitcoin have been observed in the wallet yet, and the ransom amount remains unspecified, possibly indicating the campaign’s early stages.

Indicators of Compromise (IoC) associated with this threat can be found on Cisco Talos’ GitHub repository.

Source link

Mimics operation Ransomware Traits VietnameseOrigin WannaCry
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Willy Woo Sees 20%-40% Chance of Partial Coldcard Bitcoin Recovery

August 4, 2026

Malicious smart contracts tricked 5,742 crypto victims

August 3, 2026

Bitcoin Wasn’t Hacked in Coldcard Attack, Pompliano Explains

August 3, 2026

ZachXBT Refuses to Trace the $88M Coldcard Hack

August 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Media Streaming Market Key Drivers, Opportunities, Leading Players And Forecast To 2033

October 7, 2024

BTC appears set for re-test of February’s lows

June 2, 2026

Shanghai’s Crytocurrency Tax Guide Fuels China Crypto Ban Relief Rumors

January 9, 2024

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Flowra Adds Compliance Rules to Solana

August 4, 2026

Kraken delisted tokens face liquidation, users could get $0

August 4, 2026

ONDO loses key support as team dumps 20M tokens: Can bulls hold on?

August 4, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$64,089.001.10%
  • ethereumEthereum(ETH)$1,869.490.00%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$592.000.90%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.080.30%
  • solanaSolana(SOL)$73.900.90%
  • tronTRON(TRX)$0.3289280.80%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.010.50%
  • HyperliquidHyperliquid(HYPE)$54.533.50%