ITHKRPAW is a malware delivery campaign identified in January that targeted organizations in Vietnam, particularly in the financial sector. The activity used a malicious shortcut file as the initial lure, which invoked Cloudflare Workers to deliver a PowerShell-based dropper. That dropper retrieved a secondary payload from a Hugging Face dataset repository while displaying a benign decoy image to mask malicious execution. The campaign is part of a broader pattern of threat activity abusing trusted AI-related platforms as staging and distribution infrastructure for malware. Observed tradecraft in ITHKRPAW includes initial access through a malicious LNK file, staged payload retrieval through intermediary web infrastructure, and defense evasion through decoy content intended to reduce user suspicion. The infection chain demonstrates abuse of legitimate cloud and AI-hosting services to blend malicious traffic with normal activity. Researchers also assessed with moderate confidence that the PowerShell component contained signs of machine-generated code, including embedded Vietnamese-language comments, but that assessment is not sufficient to attribute the campaign to a specific actor or state sponsor. No high-confidence attribution to a named intrusion set, criminal group, or nation-state operator is currently available. ITHKRPAW is best characterized as a distinct malware distribution campaign focused on Vietnamese financial targets and leveraging cloud-hosted staging infrastructure and social-engineering-style execution flow.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Campaign abusing Hugging Face repositories as staging infrastructure to target Vietnamese financial organizations with a multi-stage infection chain.
Malware delivery campaign abusing Hugging Face repositories and Cloudflare Workers to stage and drop payloads disguised as benign files, including a fake update assistant, with targeting focused on financial-sector organizations and entities in Vietnam.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.