Cisco Talos reported an ongoing ransomware campaign by an unidentified threat actor, assessed with moderate confidence to be of Vietnamese origin, using a customized Yashma payload derived from Chaos ransomware v5. The actor has targeted organizations across English-speaking countries as well as Bulgaria, China, and Vietnam, and attempted to imitate WannaCry through its ransom note language and desktop wallpaper. The campaign stood out for using multilingual ransom notes hosted in an attacker-controlled GitHub repository rather than embedding the text directly in the malware binary.
The modified ransomware also used persistence mechanisms including the Windows Run registry key and a startup-folder .url file that pointed to %AppData%\Roaming\svchost.exe. Talos said the malware preserved Yashma’s anti-recovery behavior by overwriting original files with a question mark character before deleting them, making forensic recovery more difficult. Reporting on the broader Chaos/Yashma lineage indicates the operation relied on a known ransomware family that has been reworked for customized deployment and evasion.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Cisco Talos reported that the unidentified threat actor's ransomware operation had been active since at least June 4, 2023, targeting victims in English-speaking countries, Bulgaria, China, and Vietnam with a customized Yashma variant.
On June 4, 2023, the actor created a public GitHub repository named "Ransomware" under the account "nguyenvietphat" to host multilingual ransom note files downloaded by the malware.
The unidentified ransomware actor's customized Yashma sample was compiled on June 4, 2023, marking the earliest explicit technical anchor for the campaign activity described by Talos.
Chaos ransomware v5, the family from which Yashma was later rebranded, appeared in May 2022 according to the Talos reference.
Cisco Talos disclosed an ongoing ransomware campaign using a customized Yashma variant and assessed with moderate confidence that the actor may be of Vietnamese origin, while detailing the malware's GitHub-based ransom note delivery and persistence mechanisms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.