vsphim is a threat-actor handle and Packagist vendor namespace associated with a malicious software supply-chain campaign targeting Composer website themes used by Vietnamese movie and comic streaming sites. Trojanized themes retained expected functionality while adding browser-side JavaScript loaders, causing affected sites to serve malicious code to visitors. The loaders fingerprint device characteristics, referral source, and iOS version; avoid desktop browsers, automated scanners, and direct visitors; redirect some mobile users to gambling content; and selectively deliver an iPhone exploit chain to qualifying victims. The iPhone-focused activity targeted older iOS versions through WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 and deployed spyware capable of collecting Keychain data, Wi-Fi passwords, messages, contacts, photos, browser cookies, call history, location records, and account data. Collected information was encrypted and exfiltrated to rotating command-and-control infrastructure. A later observed spyware variant searched Keychain data for cryptocurrency-wallet seed phrases and mnemonic recovery material. vsphim is associated with the broader campaign alongside the vsmov, haiau009, chilltvcms, and ophimcms namespaces.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with the malicious Composer-theme campaign used to compromise streaming websites and expose visitors to selective iPhone exploitation, device-data theft, cryptocurrency-wallet recovery-phrase theft, and gambling redirects.
Associated with the malicious Composer-theme campaign delivering selective iPhone exploitation, spyware, data theft, and cryptocurrency-wallet recovery-phrase theft to visitors of compromised streaming websites.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.