CoralRaider is a financially motivated Vietnamese threat actor using RotBot loader and XClient stealer.
Analyst brief
CoralRaider is a financially motivated threat actor of Vietnamese origin, active since at least 2023. They primarily target victims in Asian and Southeast Asian countries. Their key TTPs include the RotBot loader family and XClient stealer for data exfiltration, with hardcoded Vietnamese words in payloads and utilization of a Telegram bot as a C2 channel. Defenders should monitor Telegram-based C2 traffic, focus on detecting RotBot/XClient activity, and be alert to financially driven cyber espionage in the region.
CoralRaider
unknown
CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They use the RotBot loader family and XClient stealer to steal victim information, with hardcoded Vietnamese words in their payloads. CoralRaider operates from Hanoi, Vietnam, and uses a Telegram bot as a C2 channel for their malicious campaigns. Their activities include system reconnaissance, data exfiltration, and targeting victims in multiple countries in the region.