REF2754 is an intrusion set targeting large public companies in Vietnam, including financial-services and agribusiness organizations. The activity uses a Windows-focused malware stack comprising the SPECTRALVIPER backdoor, P8LOADER PE loader, POWERSEAL PowerShell runner, and DONUTLOADER. SPECTRALVIPER supports encrypted HTTP and named-pipe command and control, payload loading, process hollowing and shellcode injection, file and directory operations, file transfer, token impersonation, privilege adjustment, and process enumeration. P8LOADER executes PE payloads from disk or memory and can redirect output and log API activity, while POWERSEAL executes PowerShell commands and scripts using AMSI and ETW bypass methods. Observed execution chains include malicious-DLL loading through abused legitimate utilities, DLL side-loading, SMB-based propagation from a previously compromised endpoint, and injection into Windows processes. REF2754 has been assessed with moderate confidence as Vietnamese state-affiliated activity overlapping with Canvas Cyclone, APT32, and OceanLotus.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
21 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
13 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An intrusion set conducting campaigns against large, nationally important public companies in Vietnam using DONUTLOADER, SPECTRALVIPER, P8LOADER, and POWERSEAL for backdoor access, PE loading/injection, PowerShell execution, persistence, and intelligence gathering.
An ongoing cyber-espionage campaign against nationally important Vietnamese public companies, including an agribusiness. The group deploys DONUTLOADER, SPECTRALVIPER, P8LOADER, and POWERSEAL to maintain backdoor access, collect intelligence, evade defenses, and manipulate files and processes.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.