Full Report
Group-IB identifies massive campaign capable of targeting clients of major Vietnamese banks
Analysis Summary
# Incident Report: Massive Phishing Campaign Targeting Vietnamese Banking Clients
## Executive Summary
Group-IB identified a large-scale phishing campaign targeting clients of major Vietnamese banks, utilizing over 240 interconnected domains to harvest sensitive personal and financial data. The attackers employed sophisticated social engineering, including fake social media ads and sense-of-urgency messaging, to trick users into providing credentials and One-Time Passwords (OTPs). The campaign has resulted in the potential compromise of thousands of users, with stolen data reportedly appearing for sale on underground markets.
## Incident Details
- **Discovery Date:** May 2023 (Active campaign monitoring)
- **Incident Date:** Ongoing since at least late 2022/early 2023
- **Affected Organization:** Multiple major Vietnamese banks (unnamed) and their clients
- **Sector:** Financial Services / Banking
- **Geography:** Vietnam
## Timeline of Events
### Initial Access
- **Date/Time:** Ongoing
- **Vector:** Social Engineering (Phishing)
- **Details:** Attackers created fake Facebook pages masquerading as legitimate bank customer service or promotional offers. Victims were lured via malicious ads promising gifts, high-interest rates, or urgent account security updates.
### Lateral Movement
- **Details:** N/A. This was an external-facing campaign targeting end-users rather than a direct breach of bank internal networks. Movement occurred via redirection through a complex network of over 240 phishing domains.
### Data Exfiltration/Impact
- **Details:** User data entered into phishing forms was sent to attacker-controlled C2 (Command and Control) servers. Stolen data included full names, phone numbers, bank account credentials, and intercepted OTPs, allowing for unauthorized transactions.
### Detection & Response
- **How it was discovered:** Group-IB's Digital Risk Protection system identified a spike in malicious domains misusing Vietnamese bank brands.
- **Response actions taken:** Group-IB's CERT-GIB notified affected financial institutions and worked with registrars and hosting providers to take down malicious domains.
## Attack Methodology
- **Initial Access:** Phishing links distributed via Facebook ads and posts.
- **Persistence:** Use of a vast domain infrastructure (240+ sites) to ensure that if one site was blocked, others remained active.
- **Defense Evasion:** Use of long redirection chains and malfunctioning website elements to mimic poor mobile UI, distracting users from URL scrutiny.
- **Credential Access:** Web-based forms designed to harvest usernames, passwords, and 2FA/OTP codes in real-time.
- **Discovery:** Mapping of user behavior through social media engagement.
- **Collection:** Automated scripts gathering PII and financial credentials from form submissions.
- **Exfiltration:** Data sent via HTTP requests to attacker-managed backends.
- **Impact:** Financial loss for users and reputational damage to banks.
## Impact Assessment
- **Financial:** High potential for direct financial theft from victim accounts; costs associated with incident response for banks.
- **Data Breach:** Compromise of PII (names, phones) and highly sensitive banking credentials.
- **Operational:** Increased load on bank customer support and fraud departments.
- **Reputational:** Public trust in digital banking services eroded by brand impersonation.
## Indicators of Compromise
- **Network Indicators:** (Over 240 domains, examples defanged)
- hxxps[://]traothuong-vpb[.]com
- hxxps[://]vpb-online[.]com
- hxxps[://]khuyenmai-vpb[.]cc
- **Behavioral Indicators:**
- Facebook pages with low follower counts running high-budget ads for banking rewards.
- Redirection chains leading away from official bank domains (e.g., .com.vn).
## Response Actions
- **Containment:** Coordinated takedown requests for identified phishing URLs.
- **Eradication:** Monitoring underground forums for the sale of harvested Vietnamese banking data.
- **Recovery:** Advising banks to reset credentials for compromised users and issue public security warnings.
## Lessons Learned
- **Key Takeaways:** Social media platforms remain a primary delivery vector for financial fraud due to the ease of creating believable fake brand personas.
- **Improvements:** Banks need faster automated detection of brand impersonation outside of their own infrastructure.
## Recommendations
- **For Users:**
- Enable hardware-based 2FA or app-based tokens instead of SMS OTP where possible.
- Verify all "promotional" links via the bank’s official mobile app rather than clicking social media links.
- **For Organizations:**
- Implement AI-powered Digital Risk Protection to monitor for brand abuse in real-time.
- Enhance customer education regarding the bank's official communication channels.
- Collaborate with regional CERTs to share threat intelligence on active phishing clusters.