Attackers compromised the Vietnam Government Certification Authority (VGCA) website, ca.gov.vn, and replaced two legitimate Government Certification Authority digital-signature toolkit installers with trojanized MSI packages that deployed the PhantomNet backdoor. The malicious installers were hosted on the official HTTPS site from at least July 23 to August 16, 2020, requiring victims to manually download and run them. The packages reportedly dropped a legitimate application alongside a malicious component to reduce suspicion, turning a trusted software source into a delivery channel for malware.
Once executed, PhantomNet established persistence as either a Windows service or a scheduled task depending on user privileges, then communicated over HTTPS with hardcoded command-and-control domains using certificate pinning. ESET said the malware supported plugins, including one observed component that appeared capable of credential theft and lateral movement through embedded Invoke-Mimikatz functionality. ESET notified VGCA and Vietnam’s national computer emergency response team in December 2020, while VGCA said it was already aware of the compromise and had informed affected users.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
On December 17, 2020, ESET disclosed Operation SignSight, describing a 2020 supply-chain attack against the Vietnam Government Certification Authority website involving trojanized digital-signature toolkit installers and the PhantomNet backdoor.
In December 2020, ESET notified the Vietnam Government Certification Authority and VNCERT about the supply-chain compromise. VGCA said it was already aware of the incident and had notified affected users.
The compromise of the VGCA website appears to have lasted until August 16, 2020, ending the period during which victims could manually download the malicious installers from the official HTTPS site.
From at least July 23, 2020, attackers replaced two legitimate installers on the Vietnam Government Certification Authority website, ca.gov.vn, with trojanized MSI packages carrying the PhantomNet backdoor as part of a supply-chain attack.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.