A Vietnamese cybercrime group known as BatShadow has launched a sophisticated phishing campaign targeting job seekers and digital marketing professionals. The campaign employs social engineering tactics, with attackers posing as recruiters and distributing malicious files disguised as job descriptions and corporate documents. Victims receive phishing emails containing ZIP archives that include decoy PDF documents and hidden malicious files, such as shortcut (LNK) or executable files masked as PDFs. When these files are opened, they trigger an infection chain that delivers a previously undocumented Go-based malware called Vampire Bot. The infection process involves the execution of embedded PowerShell scripts, which reach out to external servers to download additional payloads, including lure documents and remote desktop connection software like XtraViewer. The attackers use clever techniques to bypass browser security, instructing victims to use Microsoft Edge for downloads, as scripted pop-ups and redirects are more likely to be blocked in other browsers like Chrome. Once installed, Vampire Bot provides persistent access to compromised systems and is capable of continuous desktop surveillance. The malware captures screenshots at configurable intervals, compresses them into WEBP format, and exfiltrates them over encrypted channels, giving operators substantial visibility and control over victim machines. Vampire Bot also checks in with its command and control server for new commands and can download further payloads to expand its capabilities. The campaign demonstrates BatShadow's evolution from using commodity malware to deploying custom, advanced surveillance tools. The group is part of a growing number of cybercrime gangs operating out of Vietnam, with a history of targeting both domestic and foreign organizations. The use of job-themed lures and the focus on digital marketing professionals suggest a deliberate targeting strategy aimed at individuals likely to open unsolicited job offers. Security researchers have highlighted the persistent and stealthy nature of Vampire Bot, which is designed to evade detection and maintain long-term access to infected systems. The campaign underscores the ongoing threat posed by social engineering attacks and the need for heightened vigilance among job seekers and professionals receiving unsolicited emails. Organizations are advised to educate their users about the risks of opening unexpected attachments and to implement robust endpoint protection measures. The emergence of Vampire Bot also signals a trend toward more targeted and technically sophisticated malware campaigns in the cybercrime landscape.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Security reporting identified a BatShadow threat campaign using a new Go-based malware family dubbed 'Vampire Bot' to target people seeking jobs. Multiple outlets described the same operation as focused on luring and infecting job hunters.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.