Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to threat actors

viettel_cyber_security

Also known asViettel Cyber Security

Viettel Cyber Security is identified in the provided content as a security research team participating in the Pwn2Own Ireland competitions. At Pwn2Own Ireland 2024, Viettel Cyber Security earned $205,000 after exploiting QNAP, Sonos, and Lexmark flaws. At Pwn2Own Ireland 2025, Dinh Ho Anh Khoa and Phan Vinh Khang of Viettel Cyber Security successfully exploited Home Automation Green using a unique command injection bug and two additional bugs that collided with previously reported issues, earning $12,500 and 2.75 Master of Pwn points. Based on the provided content, the commonly used name and alias is Viettel Cyber Security. No high-confidence information in the content attributes this entity to malicious activity, a nation-state, or additional sub-groups.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

3 of 15 tactics3 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0002
Execution
1 technique
T1203
Exploitation for Client Execution
TA0004
Privilege Escalation
1 technique
T1068×2
Exploitation for Privilege Escalation
TA0007
Discovery
1 technique
T1083
File and Directory Discovery
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping3

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.