Vietnam.vn - Nền tảng quảng bá Việt Nam

Android phones in Vietnam are being targeted by attacks

Security group BKAV has just issued a warning that a campaign using RedHook malware to steal personal data, bank accounts and take control of devices is deliberately targeting Vietnamese users on mobile devices running the Android operating system.

Báo Sài Gòn Giải phóngBáo Sài Gòn Giải phóng07/08/2025

Data on the victim's phone is compressed with gzip and sent to the C&C server.
Data on the victim's phone is compressed with gzip and sent to the C&C server.

Hackers create fake websites of government agencies or reputable financial institutions such as: State Bank of Vietnam (SBV), Sacombank (Sacombank Pay), Central Power Corporation (EVNCPC), Automobile Inspection Appointment System (TTDK)... install malware under the guise of applications, then trick users into downloading them to their phones, using many different scenarios such as sending emails, texting via chat applications or running ads on search engines...

The fake app is disguised with the same name as the real app, only with a different extension (e.g. SBV.apk) and is stored on the Amazon S3 cloud, making it easy for hackers to update, change, and hide malicious content. Once installed, the fake app asks the user to grant deep system access, including Accessibility and Overlay permissions.

Combining these two rights, hackers can monitor user operations, read SMS message content, get OTP codes, access contacts, and even operate on behalf of users without leaving any obvious signs.

Screenshot 2025-08-07 at 10.42.30.png

By decompiling the source code of RedHook, experts from Bkav's Malware Analysis Center discovered that the virus integrates up to 34 remote control commands, including taking screenshots, sending and receiving messages, installing or uninstalling applications, locking and unlocking devices, and executing system commands. They use the MediaProjection API to record all content displayed on the device screen and then transfer it to the control server.

RedHook has a JSON Web Token (JWT) authentication mechanism, which helps attackers maintain control of the device for a long time, even when the device is rebooted.

During the analysis, Bkav discovered many code segments and interface strings using Chinese language along with many other clear traces of the hacker group's development origin as well as the RedHook distribution campaign related to fraudulent activities that have appeared in Vietnam.

For example, the use of the domain name mailisa[.]me, a popular beauty service that has been exploited in the past, to spread malware shows that RedHook is not operating alone but is the product of a series of organized attacks, which are sophisticated in both technical and tactical aspects. The control server domains used in this campaign include api9.iosgaxx423.xyz and skt9.iosgaxx423.xyz, both of which are anonymous addresses located overseas and cannot be easily traced.

Bkav recommends that users absolutely do not install applications outside of Google Play, especially APK files received via text messages, emails or social networks. Do not grant access rights to applications of unknown origin. Organizations need to deploy access monitoring measures, DNS filtering and set up warnings for connections to unusual domains related to the malware's control infrastructure. If you suspect an infection, immediately disconnect from the Internet, back up important data, perform a factory reset, change all account passwords, and contact your bank to check the status of your account.

Source: https://www.sggp.org.vn/dien-thoai-android-tai-viet-nam-dang-bi-tan-cong-co-chu-dich-post807230.html


Comment (0)

No data
No data
Southeast Asian newspapers comment on the resounding victory of the Vietnamese women's team
Wild beauty on Ha Lang grass hill - Cao Bang
Vietnam Air Force practices preparing for A80
Missiles and combat vehicles 'Made in Vietnam' show off their power at A80 joint training session
Admire the million-year-old Chu Dang Ya volcano in Gia Lai
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground

Heritage

Figure

Business

No videos available

News

Political System

Destination

Product