Also known as: said, tracked as, expert insights, intelligence updates, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Mustang Panda, BRONZE PRESIDENT, RedDelta, Luminous Moth, Earth Preta, Royal Ransomware, Camaro Dragon
BatShadow emerged from Vietnam and has built its reputation around social engineering that targets individuals actively searching or working in digital marketing roles. The group employs recruiter‑style emails that appear legitimate, delivering malicious job descriptions or corporate PDFs which, when opened, launch a multi‑stage infection pipeline. The payload is a Go‑compiled executable – the newly dubbed Vampire Bot – that combines data exfiltration, remote monitoring, and credential theft capabilities. Historically, BatShadow’s toolbox has evolved from Agent Tesla stealer to Lumma Stealer and Venom RAT before consolidating around Vampire Bot. This evolution shows a focus on low‑cost, high‑gain operations: the attackers aim primarily for financial gain through account hijacking (e.g., compromised Facebook business accounts) or double‑extortion tactics involving data theft and ransomware threats. Their targeting pattern indicates a strong emphasis on phishing rather than exploitation of zero‑day vulnerabilities. The group’s infrastructure includes the Vietnamese IP 103.124.95.161, which has been linked to other Vietnam‑based actors, providing a rough attribution anchor. While the actors claim broad sectoral interests—government, finance, education, defense, healthcare and more—the publicly documented campaigns chiefly impact digital marketing professionals across these sectors. Defense analysis shows that BatShadow leverages common phishing tactics such as filename tricks (“update.exe.pdf”) and coercive browser warnings, coupled with Go binaries to bypass traditional signature‑based defenses. The use of encrypted payloads via HTTP/HTTPS and occasional DNS tunneling suggests an adaptive approach to maintaining persistence and exfiltration channels.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
BatShadow is a financially motivated Vietnamese threat actor that lures job seekers and digital marketing professionals through deceptive recruiter emails containing malicious PDFs or documents. The campaigns deploy a Go‑based malware called Vampire Bot, which installs credential stealers and enables remote surveillance. Recent activity links the group to IP 103.124.95.161 and domain usage such as samsung-work.com for distribution.
Goals & Targeting
BatShadow’s strategic objective is financial gain through the theft of credentials from targeted individuals, notably digital marketing professionals and job seekers, who are more likely to engage with recruiter‑style emails. Their broad sectoral claims allow them to focus on any organization with a large number of internet‑exposed users: government agencies, finance firms, education institutions, healthcare facilities, defense contractors, media outlets, retailers and various service providers. By compromising individuals in organizations that manage online advertising or public‑facing services, the group can hijack social media or e‑commerce accounts for fraudulent marketing, generating revenue from account takeover fees or double‑extortion. The selection of countries—KP, CN, RU, IN, UA, GB, DE, IR, PK, BY, PL, TW, CA, AU—suggests a preference for regions with high numbers of digital marketers and job seekers. The primary victim type is the individual worker (the recruiter or employee), not necessarily the organization as a whole; however, compromised credentials can provide attackers with back‑doors into corporate networks. Overall, BatShadow appears to be organized but primarily opportunistic, leveraging reusable infrastructure rather than highly sophisticated nation‑state capabilities.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
BatShadow’s known campaigns have largely centered on job‑seeker phishing and involve the deployment of Vampire Bot via email attachments. The actors reuse infrastructure such as Vietnamese IP 103.124.95.161 across multiple malware families, reflecting a modular approach to tooling. Their operational tempo appears relatively steady, with annual or semi‑annual waves targeting digital marketing communities. While some reports list wide‑range sectors and countries, the publicly documented attacks have predominantly impacted individuals rather than entire organizations, suggesting that the group’s focus lies in leveraging compromised credentials for financial exploitation. Notable past operations include earlier use of Agent Tesla to hijack Facebook business accounts and a shift toward Go‑based malware in 2025. The actor has not yet demonstrated extensive ransomware deployment; however, double‑extortion tactics (T1657 and T1486) are listed as potential future capabilities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based primarily on a single 2025–2026 Palo Alto Networks Unit 42 write‑up and associated article reporting Vampire Bot deliveries to job seekers, providing solid evidence for the actor’s origin (VN), victim profile, and malware. Attribution hinges largely on IP reuse and the Vietnamese context; however, sectoral claims and country list appear broad and lack corroborating data from other independent reports, lowering confidence in those elements. Overall confidence for tactics and tools is moderate to high, while strategic objectives for each targeted sector remain inferred rather than confirmed.
No campaigns linked yet.
No observed data linked yet.
20
Techniques
43
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics