Operation Hanoi Thief is a targeted spear-phishing threat cluster focused on Vietnam, particularly IT departments and recruitment professionals. The activity uses fake resume lures delivered in phishing emails, typically as compressed attachments containing a malicious shortcut and a disguised payload. The infection chain abuses trusted Windows utilities for execution and defense evasion, then deploys a DLL implant known as LOTUSHARVEST through DLL sideloading. LOTUSHARVEST is an information-stealing payload written in C++ that harvests browser credentials and browsing history from Chromium-based browsers including Chrome and Edge, then exfiltrates the collected data over HTTPS. The campaign has also demonstrated anti-analysis checks for virtualized environments and debuggers, along with masquerading, misleading file extensions, signed binary proxy execution, and other evasion measures. Observed ATT&CK-aligned behaviors include spearphishing attachment delivery, DLL sideloading, credential theft from browser password stores, and data exfiltration. Attribution has been assessed with moderate confidence as a Chinese-origin threat cluster based on tactical overlaps with earlier activity targeting Vietnam, although state sponsorship has not been confirmed. Known aliases are limited to naming variants derived from the campaign label itself, and no distinct sub-groups are established at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Operation Hanoi Thief is a Chinese-origin threat cluster targeting Vietnamese IT and HR firms with phishing emails delivering the LOTUSHARVEST malware.
Operation Hanoi Thief is a Chinese-origin threat cluster targeting Vietnamese IT and HR firms with phishing emails delivering LOTUSHARVEST malware.
Conducting spear-phishing campaigns targeting Vietnamese IT and recruitment professionals using fake resumes and pseudo-polyglot payloads to deliver the LOTUSHARVEST information-stealing implant. The campaign focuses on credential theft and browser data exfiltration.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.