Malicious Microsoft Word documents masquerading as official Vietnamese correspondence were used in a suspected targeted campaign against victims in Vietnam, relying on template injection (T1221) to fetch remote content only when the file was opened. In one case, a .docx lure impersonating a dispatch from the Central Inspection Committee retrieved Main.jpg from 45[.]121[.]146[.]88; the file was actually a weaponized RTF that exploited an Equation Editor flaw, dropped an encoded payload 5.t into %Temp%, decoded it, and produced Download.dll, which was then executed through a scheduled task. Researchers said the lure appeared to have been created or modified with Kingsoft Office, while the DLL was built with Visual Studio 2019.
A similar sample analyzed later used a Word document to retrieve fav.ico from office[.]oiqezet[.]com, but that file also concealed an RTF with an embedded encrypted object that ultimately unpacked into another Download.dll. That malware collected host, operating system, user, internet, and antivirus information, encrypted the data with RC4 using the key 123abc, Base64-encoded it, and exfiltrated it to log.php on the same domain. The tradecraft matches MITRE ATT&CK's Template Injection technique, which allows attackers to hide payload delivery behind external template references and avoid obvious macro-based indicators, and one analysis noted code similarities to an earlier APT Panda campaign targeting Vietnam.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
A malicious Word document named "Bien ban thong nhat ke hoach dao tao_VPB.Voffice.docx" was submitted from Vietnam. Later analysis found it used template injection to retrieve an RTF disguised as fav.ico, decode an embedded object into Download.dll, and exfiltrate victim system information to log.php on the same domain.
VinCSS reported that the decrypted DLL payload, Download.dll, carried a PE TimeDateStamp of 2021-04-01 01:59:48 UTC. The researchers said the timestamp was consistent across the PE header and debug information.
A public analysis described a second malicious document highlighted by Shadow Chaser Group that used template injection and an RTF payload to deliver Download.dll. Reverse engineering showed the DLL collected host, OS, user, internet, and antivirus information, encrypted it with RC4 using the key "123abc," and Base64-encoded it before exfiltration.
VinCSS analyzed a lure document impersonating an official Central Inspection Committee dispatch and assessed it as likely part of a cyberattack campaign targeting Vietnam. The document used template injection to fetch a remote RTF disguised as Main.jpg, which exploited an Equation Editor flaw to drop and execute Download.dll via a scheduled task.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 9 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
3 references tracked. Mallory keeps watching after this page renders.
kienmanowar.wordpress.com
Open sourceblog.vincss.net
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.