Close Menu
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
What's Hot

Bitcoin Has a Built-In Price Floor Driven by Energy Costs

June 5, 2026

Has The Bitcoin Crash Ended After Falling Below $70,000?

June 5, 2026

Crypto PACs go undefeated in June primaries as Fairshake scores bipartisan winning streak

June 5, 2026
Facebook X (Twitter) Instagram
  • Contact
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
CryptoPulseDaily.com
  • Latest News
    • Market
    • Altcoins
    • Legal and Regulatory
  • Tech
    • Blockchain
    • Security and Privacy
  • Web 3
    • Web3 News
    • NFTs
    • Gaming
  • Learn
    • Education
    • Investments
    • Staking
    • Wallets and Exchanges
  • ICOs
  • Mining
  • Crypto Tools
    • Exchange Tool
  • Shop
CryptoPulseDaily.com
Home»Security and Privacy»Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits
Security and Privacy

Vietnamese-Origin Ransomware Operation Mimics WannaCry Traits

August 8, 2023No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email

An unidentified threat actor, reportedly originating from Vietnam, has been observed engaging in a ransomware campaign that commenced no later than June 4 and employing a variant of the Yashma ransomware, showcasing similarities to the infamous WannaCry ransomware.

According to a new advisory published by Cisco Talos on Monday, what sets this operation apart is the novel approach to delivering ransom notes. 

Instead of embedding ransom note strings within the malware binary, the attackers execute a batch file to retrieve the ransom note from their GitHub repository. This tactic provides a level of evasion against traditional endpoint security measures.

Talos’ analysis also indicated that the threat actor appears to target English-speaking countries, Bulgaria, China and Vietnam. The GitHub account linked to the attacker features ransom notes in languages associated with these regions. 

Furthermore, clues suggest a Vietnamese origin for the threat actor. The GitHub account’s name and email contact mimic a legitimate Vietnamese organization’s details, and the ransom note specifies contact hours in UTC+7, coinciding with Vietnam’s time zone.

The attackers also exhibited a heightened sensitivity towards Vietnamese victims, initiating their ransom note with an apologetic tone. This subtle linguistic variation might point to the attackers being Vietnamese.

The ransomware variant employed is a customized version of Yashma, with the actor compiling it on June 4, 2023. This .NET-based malware retains Yashma’s anti-recovery capability, erasing unencrypted files after encryption to impede recovery efforts.

Read more on Yashma: Emsisoft Releases Free Decryptor For AstraLocker and Yashma Ransomware

At present, the attackers demand ransom payments in Bitcoin to an identified wallet address and double the ransomware price if the victim fails to pay within three days. 

See also  North Korean Group TA444 Shows 'Startup' Culture, Tries Numerous Infection Methods

However, no Bitcoin have been observed in the wallet yet, and the ransom amount remains unspecified, possibly indicating the campaign’s early stages.

Indicators of Compromise (IoC) associated with this threat can be found on Cisco Talos’ GitHub repository.

Source link

Mimics operation Ransomware Traits VietnameseOrigin WannaCry
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Infosecurity Europe: AI-Powered Cybercrime Tools Surge on Dark Web

June 3, 2026

Stake DAO Freezes Arbitrum vsdCRV Markets After Attacker Mints 5.4T Synthetic Tokens

May 29, 2026

Certik Unveils ‘Anti-Virus for AI Agents’ as Skill Marketplaces Face Hidden Threats

May 29, 2026

New Threat Actor Jinx-0164 Targets Crypto Developers on macOS

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Ripple Provides Major Update on XRP Case Versus SEC: Here’s What’s Next

November 3, 2023

Ethereum resurgence and layer-2 boom define crypto Q2: IntoTheBlock

June 30, 2024

Somebody extradite Do Kwon already

March 14, 2026

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

Our mission is to develop a community of people who try to make financially sound decisions. The website strives to educate individuals in making wise choices about Crypto, ICOs, Web3, Blockchain and more.

We're social. Connect with us:

Facebook X (Twitter) Instagram Pinterest YouTube
Top Insights

Bitcoin Has a Built-In Price Floor Driven by Energy Costs

June 5, 2026

Has The Bitcoin Crash Ended After Falling Below $70,000?

June 5, 2026

Crypto PACs go undefeated in June primaries as Fairshake scores bipartisan winning streak

June 5, 2026
Get Informed

Subscribe to Updates

Get the latest creative news From Crypto Daily Pulse directly in your Inbox!

  • Contact
  • Privacy Policy
  • Terms & Conditions
© 2026 Crypto Pulse Daily - All rights reserved.

Type above and press Enter to search. Press Esc to cancel.

Cleantalk Pixel
  • bitcoinBitcoin(BTC)$62,783.00-0.85%
  • ethereumEthereum(ETH)$1,736.64-2.00%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$598.34-1.54%
  • usd-coinUSDC(USDC)$1.000.01%
  • rippleXRP(XRP)$1.14-3.05%
  • solanaSolana(SOL)$67.90-2.90%
  • tronTRON(TRX)$0.327367-1.18%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.021.81%
  • HyperliquidHyperliquid(HYPE)$64.97-11.23%