Secureworks reported that the TIN WOODLAWN cyberespionage group used a modified version of Cobalt Strike in targeted intrusions designed to evade standard security detections. The activity was attributed to a threat group likely operated or tasked by the Vietnamese government, with operations focused on stealing intellectual property and trade secrets as well as targeting journalists and political opponents of interest to Vietnam.
In the observed attacks, the group used spearphishing attachments consistent with MITRE ATT&CK technique T1598.002 to deliver malicious documents, then relied on macro code to create scheduled tasks and abused mshta to fetch an in-memory PowerShell Beacon stager. Secureworks said the actors also deployed a custom stager, CommaChameleon, which used the unusual PowerShell -comma switch with randomized casing, received an RC4-encrypted payload through a named pipe, and injected it into legitimate Windows processes such as esentutl.exe, underscoring a layered evasion approach associated with a sophisticated state-backed actor.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
Secureworks CTU reported that TIN WOODLAWN used a custom stager it named CommaChameleon, which leveraged the shortened PowerShell '-comma' switch with randomized casing, received an RC4-encrypted payload through a named pipe, and injected it into legitimate Windows processes. In one campaign, the injected payload included Mimikatz for credential theft via esentutl.exe.
Secureworks CTU assessed that TIN WOODLAWN is likely operated or tasked by the Vietnamese government. The group was described as conducting espionage to steal intellectual property and trade secrets and targeting journalists and political opponents of interest to Vietnam.
Secureworks incident responders observed the TIN WOODLAWN cyberespionage group using a modified version of Cobalt Strike during targeted intrusions to evade detections based on default configurations. The activity included spearphishing-delivered malicious documents, scheduled tasks, mshta abuse, in-memory PowerShell Beacon staging, and use of the custom CommaChameleon stager.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.