vsmov is a threat-actor handle and Packagist vendor namespace associated with a software supply-chain campaign targeting Vietnamese movie and comic streaming websites. The campaign distributed trojanized Composer themes that preserved expected theme functionality while adding browser-side JavaScript loaders. Installation of an affected theme caused malicious code to be served to visitors of the compromised website. The loaders fingerprint device characteristics, referral sources, and browser context, and selectively avoid desktop systems, automated analysis, and direct visitors. Some mobile visitors are redirected to gambling content, while selected iPhone users are routed into an exploit chain targeting the patched WebKit vulnerabilities CVE-2025-31277 and CVE-2025-43529 on older iOS versions. The chain performs iOS-version detection, deploys additional exploit stages, and installs spyware. The spyware collects sensitive iPhone data, including Keychain data, Wi-Fi passwords, messages, contacts, photos, browser cookies, call history, location records, and account data. Collected information is encrypted before exfiltration to rotating command-and-control infrastructure. A later observed variant added cryptocurrency theft by searching Keychain contents for wallet seed phrases and mnemonic recovery material. The campaign has also been associated with the Packagist namespaces vsphim, haiau009, chilltvcms, and ophimcms.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with a software-supply-chain campaign that trojanizes Composer themes used by Vietnamese movie and comic streaming sites. The injected JavaScript profiles visitors, redirects some mobile users to gambling content, and delivers an iPhone exploit-and-spyware chain to selected targets.
Associated with a malicious Composer-theme supply-chain campaign that injects JavaScript loaders into streaming-site themes. The campaign selectively targets iPhone visitors with WebKit exploitation and spyware that steals device data and cryptocurrency-wallet recovery material.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.