Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors CoralRaider

Description

CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They use the RotBot loader family and XClient stealer to steal victim information, with hardcoded Vietnamese words in their payloads. CoralRaider operates from Hanoi, Vietnam, and uses a Telegram bot as a C2 channel for their malicious campaigns. Their activities include system reconnaissance, data exfiltration, and targeting victims in multiple countries in the region.

AI Analysis

· 1 week ago

Executive Summary

CoralRaider is a Vietnamese-based cyber threat actor targeting individuals and organizations across Southeast Asia since 2023. Known for using RotBot loader and XClient stealer malware, they aim to steal sensitive information with hardcoded Vietnamese language strings in their payloads. Their command-and-control infrastructure leverages Telegram bots, indicating an operational approach that emphasizes security through non-traditional communication channels.

Goals & Targeting

CoralRaider's primary motivation appears to be financial gain, likely through the theft of personal and financial information from their victims. Their targeting focus on Southeast Asian countries may stem from both geographic proximity and the potential for lower detection rates in certain regions. The use of localized language elements in their payloads could also indicate an attempt to target Vietnamese-speaking victims more effectively. This group's strategic objectives include compromising systems to extract valuable data, which they can then monetize through sale or other malicious activities.

Enhanced Description

CoralRaider emerged in 2023 as a financially motivated threat group based in Hanoi, Vietnam. They primarily target victims in Southeast Asian countries, utilizing the RotBot loader family and XClient stealer malware to compromise systems and extract sensitive information. The inclusion of Vietnamese language strings within their payloads suggests a potential connection to their geographic origin and may aid in evading detection by security tools not tailored to detect such indicators. CoralRaider's operational tactics include system reconnaissance and data exfiltration, with their campaigns often leveraging phishing emails as an initial attack vector. Their use of a Telegram bot for command-and-control (C2) communication indicates a level of operational sophistication aimed at avoiding traditional monitoring techniques.

Key Capabilities

  • Malware development and deployment (RotBot loader family, XClient stealer)
  • Use of Telegram bots for command-and-control
  • System reconnaissance
  • Data exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Discovery
Lateral Movement
Exfiltration
Collection

ATT&CK Techniques

T1059.003 - Spear Phishing Attachment
T1048 - Exfiltration Over Unencrypted Network
T1070 - Lateral Movement via PsExec
T1003 - Malware Execution: Script-Based Injection

Software / Tooling

RotBot Loader
XClient Stealer
Telegram Bot (C2)

Campaigns & Victims

CoralRaider's campaigns are characterized by their use of tailored malware and encrypted communication channels. Their operational tempo suggests a focus on stealth and persistence, with initial activities concentrated in Southeast Asia. Notable campaign patterns include spear-phishing emails with malicious attachments and the deployment of tools designed to remain under the radar. While there is limited public reporting on specific campaigns, their activity since 2023 indicates a growing presence in the cyber threat landscape.

IOC Patterns

  • Spear phishing emails targeting Southeast Asian individuals or organizations
  • Hardcoded Vietnamese language strings within malware payloads
  • Telegram bot activities correlating with malicious campaigns
  • Network traffic indicative of data exfiltration from compromised systems

Recommended Actions

  • Implement language-based detection mechanisms for binaries and scripts in Vietnamese
  • Monitor for unusual activity on Telegram accounts or channels associated with known threat actors
  • Enhance email filtering to detect spear-phishing attempts originating from Southeast Asian regions
  • Use endpoint detection and response (EDR) solutions capable of identifying RotBot and XClient signatures
  • Enforce multi-factor authentication (MFA) for critical systems and financial accounts

Suggested Tags

APT
Financial Motivation
Southeast Asia Focus
Malware Development
Cybercriminal Activity

Confidence Assessment

The confidence level in the details about CoralRaider is moderate, with sufficient evidence to establish their existence and basic capabilities. Gaps remain in understanding their exact TTPs beyond what's publicly reported and the full scope of their campaign activities outside Southeast Asia. Further intelligence sharing and analysis would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Critical Infrastructure
Backdoor / C2
Data Exfiltration
APT
Financial Motivation
Southeast Asia Focus
Malware Development
Cybercriminal Activity

Details

Type
Unknown
Country of Origin
V
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.