CoralRaider is a financially motivated threat actor of Vietnamese origin, targeting victims in Asian and Southeast Asian countries since at least 2023. They use the RotBot loader family and XClient stealer to steal victim information, with hardcoded Vietnamese words in their payloads. CoralRaider operates from Hanoi, Vietnam, and uses a Telegram bot as a C2 channel for their malicious campaigns. Their activities include system reconnaissance, data exfiltration, and targeting victims in multiple countries in the region.
Executive Summary
CoralRaider is a Vietnamese-based cyber threat actor targeting individuals and organizations across Southeast Asia since 2023. Known for using RotBot loader and XClient stealer malware, they aim to steal sensitive information with hardcoded Vietnamese language strings in their payloads. Their command-and-control infrastructure leverages Telegram bots, indicating an operational approach that emphasizes security through non-traditional communication channels.
Goals & Targeting
CoralRaider's primary motivation appears to be financial gain, likely through the theft of personal and financial information from their victims. Their targeting focus on Southeast Asian countries may stem from both geographic proximity and the potential for lower detection rates in certain regions. The use of localized language elements in their payloads could also indicate an attempt to target Vietnamese-speaking victims more effectively. This group's strategic objectives include compromising systems to extract valuable data, which they can then monetize through sale or other malicious activities.
Enhanced Description
CoralRaider emerged in 2023 as a financially motivated threat group based in Hanoi, Vietnam. They primarily target victims in Southeast Asian countries, utilizing the RotBot loader family and XClient stealer malware to compromise systems and extract sensitive information. The inclusion of Vietnamese language strings within their payloads suggests a potential connection to their geographic origin and may aid in evading detection by security tools not tailored to detect such indicators. CoralRaider's operational tactics include system reconnaissance and data exfiltration, with their campaigns often leveraging phishing emails as an initial attack vector. Their use of a Telegram bot for command-and-control (C2) communication indicates a level of operational sophistication aimed at avoiding traditional monitoring techniques.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
CoralRaider's campaigns are characterized by their use of tailored malware and encrypted communication channels. Their operational tempo suggests a focus on stealth and persistence, with initial activities concentrated in Southeast Asia. Notable campaign patterns include spear-phishing emails with malicious attachments and the deployment of tools designed to remain under the radar. While there is limited public reporting on specific campaigns, their activity since 2023 indicates a growing presence in the cyber threat landscape.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence level in the details about CoralRaider is moderate, with sufficient evidence to establish their existence and basic capabilities. Gaps remain in understanding their exact TTPs beyond what's publicly reported and the full scope of their campaign activities outside Southeast Asia. Further intelligence sharing and analysis would enhance understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics