A Vietnamese cybercriminal group known as Lone None has orchestrated a sophisticated phishing campaign that leverages fake copyright infringement notices to target individuals and organizations globally. The campaign, active since at least November 2024, begins with emails purporting to be from legitimate law firms, demanding the removal of allegedly infringing content from the recipient’s website or social media accounts. These emails are highly convincing, often referencing the recipient’s real online profiles and are translated into at least ten languages, including English, French, German, and Chinese, indicating a broad international targeting strategy. The phishing messages contain links that direct victims to download compressed archives, such as ZIP files, which masquerade as legal evidence documents in formats like PDF or PNG. Upon extraction, these archives contain malware that is executed using DLL side-loading, a technique that abuses trusted, signed applications—such as Microsoft Word or PDF readers—to bypass security controls and run malicious code undetected. The campaign delivers two primary types of information-stealing malware: Pure Logs Stealer and the more recent Lone None Stealer, also known as PXA Stealer. Pure Logs Stealer is designed to harvest a wide array of sensitive data, including passwords, credit card details, session cookies, and cryptocurrency wallet files stored on the victim’s device. The Lone None Stealer, first tracked by Cofense Intelligence in June 2025, is specifically engineered to target cryptocurrency assets. It monitors the victim’s clipboard for copied crypto wallet addresses and surreptitiously replaces them with addresses controlled by the attackers, thereby redirecting any intended cryptocurrency transfers. The campaign’s technical sophistication is further demonstrated by its use of Telegram bot profile pages for initial payload delivery and the deployment of obfuscated, compiled Python scripts to evade detection. Cofense Intelligence has observed that Lone None Stealer has appeared in 29% of all active threat reports involving Pure Logs Stealer since June 2025, highlighting its growing prevalence. The attackers also employ machine translation or AI tools to generate new email templates, allowing them to rapidly adapt and expand their reach. To further evade analysis and detection, the campaign abuses legitimate software such as Haihaisoft, leveraging their signed binaries for malicious purposes. The ongoing evolution of the campaign’s tactics, techniques, and procedures (TTPs) demonstrates a high level of operational agility and technical capability. The campaign’s focus on both personal and financial data, with a particular emphasis on cryptocurrency theft, poses significant risks to individuals and organizations alike. Security researchers recommend heightened vigilance for unsolicited legal notices, especially those containing download links or attachments, and advise organizations to implement robust email filtering and endpoint protection measures. The use of legitimate-looking legal threats and multi-language support increases the likelihood of successful social engineering, making this campaign particularly dangerous for a global audience. The campaign’s reliance on trusted software for malware execution underscores the importance of monitoring for unusual process behaviors and regularly updating security controls to detect DLL side-loading techniques. Organizations are urged to educate employees about the risks of phishing emails and to verify the authenticity of any legal correspondence received via email.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By late September 2025, reporting on the campaign revealed that Lone None was using Telegram bots both for malware staging and as a primary command-and-control channel. Researchers also tied the operation to ongoing theft of personal, financial, and cryptocurrency-related information.
Cofense reported a notable rise in the use of the newer Lone None Stealer, also called PXA Stealer, starting in June 2025. This malware focused heavily on cryptocurrency theft, including replacing copied wallet addresses to redirect funds.
In the earlier phase of the campaign, the attackers used DLL side-loading to execute malware disguised as evidence documents and deliver Pure Logs Stealer. The technique helped the malware evade security controls while harvesting victim data.
A Vietnamese threat actor tracked as Lone None began running a phishing campaign by at least November 2024, sending fake legal or copyright takedown notices to trick targets into opening malware-laced files. The operation used multilingual lures, indicating broad international targeting.
3 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcehackread.com
Open sourcecofense.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.