Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors BatShadow

Also known as: said, tracked as, expert insights, intelligence updates, BlackCat, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down, Mustang Panda, BRONZE PRESIDENT, RedDelta, Luminous Moth, Earth Preta, Royal Ransomware, Camaro Dragon

Description

BatShadow emerged from Vietnam and has built its reputation around social engineering that targets individuals actively searching or working in digital marketing roles. The group employs recruiter‑style emails that appear legitimate, delivering malicious job descriptions or corporate PDFs which, when opened, launch a multi‑stage infection pipeline. The payload is a Go‑compiled executable – the newly dubbed Vampire Bot – that combines data exfiltration, remote monitoring, and credential theft capabilities. Historically, BatShadow’s toolbox has evolved from Agent Tesla stealer to Lumma Stealer and Venom RAT before consolidating around Vampire Bot. This evolution shows a focus on low‑cost, high‑gain operations: the attackers aim primarily for financial gain through account hijacking (e.g., compromised Facebook business accounts) or double‑extortion tactics involving data theft and ransomware threats. Their targeting pattern indicates a strong emphasis on phishing rather than exploitation of zero‑day vulnerabilities. The group’s infrastructure includes the Vietnamese IP 103.124.95.161, which has been linked to other Vietnam‑based actors, providing a rough attribution anchor. While the actors claim broad sectoral interests—government, finance, education, defense, healthcare and more—the publicly documented campaigns chiefly impact digital marketing professionals across these sectors. Defense analysis shows that BatShadow leverages common phishing tactics such as filename tricks (“update.exe.pdf”) and coercive browser warnings, coupled with Go binaries to bypass traditional signature‑based defenses. The use of encrypted payloads via HTTP/HTTPS and occasional DNS tunneling suggests an adaptive approach to maintaining persistence and exfiltration channels.

Goals & Targeting

Targeted Sectors

Government
Financial services
Education
Telecommunications
Defense
Critical infrastructure
Healthcare
Manufacturing
Media
Retail
Non profit
Information technology
Hospitality
Aerospace
Maritime
Nuclear
Entertainment
Gaming
Food agriculture
Construction
Transportation
Energy

Targeted Countries / Regions

KP
CN
RU
IN
UA
GB
DE
IR
PK
BY
PL
TW
CA
AU

AI Analysis

Grounded in web research
· 17 hours ago

Executive Summary

BatShadow is a financially motivated Vietnamese threat actor that lures job seekers and digital marketing professionals through deceptive recruiter emails containing malicious PDFs or documents. The campaigns deploy a Go‑based malware called Vampire Bot, which installs credential stealers and enables remote surveillance. Recent activity links the group to IP 103.124.95.161 and domain usage such as samsung-work.com for distribution.

Goals & Targeting

BatShadow’s strategic objective is financial gain through the theft of credentials from targeted individuals, notably digital marketing professionals and job seekers, who are more likely to engage with recruiter‑style emails. Their broad sectoral claims allow them to focus on any organization with a large number of internet‑exposed users: government agencies, finance firms, education institutions, healthcare facilities, defense contractors, media outlets, retailers and various service providers. By compromising individuals in organizations that manage online advertising or public‑facing services, the group can hijack social media or e‑commerce accounts for fraudulent marketing, generating revenue from account takeover fees or double‑extortion. The selection of countries—KP, CN, RU, IN, UA, GB, DE, IR, PK, BY, PL, TW, CA, AU—suggests a preference for regions with high numbers of digital marketers and job seekers. The primary victim type is the individual worker (the recruiter or employee), not necessarily the organization as a whole; however, compromised credentials can provide attackers with back‑doors into corporate networks. Overall, BatShadow appears to be organized but primarily opportunistic, leveraging reusable infrastructure rather than highly sophisticated nation‑state capabilities.

Enhanced Description

Key Capabilities

  • Credential theft via stealer malware
  • Email phishing and spear‑phishing attachments
  • Go‑compiled payload delivery
  • Multi‑stage infection chain with remote surveillance
  • Use of filename tricks and browser coercion to evade detection
  • Credential dumping tools like Mimikatz and LaZagne
  • Exfiltration over web services
  • Limited use of encryption for data exfiltration

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Collection
Exfiltration
Impact

ATT&CK Techniques

T1566.001
T1105
T1071.001
T1059.003
T1083
T1110
T1003
T1124
T1018
T1602
T1520
T1040
T1055
T1060

Software / Tooling

Vampire Bot
Agent Tesla
Lumma Stealer
Venom RAT
Mimikatz
LaZagne
TONESHELL

Campaigns & Victims

BatShadow’s known campaigns have largely centered on job‑seeker phishing and involve the deployment of Vampire Bot via email attachments. The actors reuse infrastructure such as Vietnamese IP 103.124.95.161 across multiple malware families, reflecting a modular approach to tooling. Their operational tempo appears relatively steady, with annual or semi‑annual waves targeting digital marketing communities. While some reports list wide‑range sectors and countries, the publicly documented attacks have predominantly impacted individuals rather than entire organizations, suggesting that the group’s focus lies in leveraging compromised credentials for financial exploitation. Notable past operations include earlier use of Agent Tesla to hijack Facebook business accounts and a shift toward Go‑based malware in 2025. The actor has not yet demonstrated extensive ransomware deployment; however, double‑extortion tactics (T1657 and T1486) are listed as potential future capabilities.

IOC Patterns

  • Spear‑phishing with malicious PDFs or disguised job descriptions
  • Use of Go‐compiled executables such as Vampire Bot
  • Malicious attachment names like update.exe pdf
  • IP 103.124.95.161 for command and control
  • Domain usage including samsung‑work.com and temporary domains (TEMP.Periscope, TEMP.Hex)

Recommended Actions

  • Implement robust email filtering and sandboxing for attachments; Provide targeted phishing awareness training for recruiting and HR personnel; Block or flag inbound emails from known recruiter domains or IPs like 103.124.95.161; Enforce MFA on all external accounts, especially social media and marketing platforms; Deploy endpoint detection and response capable of detecting Go binaries and credential stealers; Patch publicly exposed web applications to remove potential exploitation vectors; Monitor for unusual outbound traffic to HTTP/HTTPS endpoints from client machines; Maintain up‑to‑date IOC feeds that include known domain, IP and file hash patterns;
  • Perform regular security audits of third‑party recruiter services and vendor communications.

Suggested Tags

APT
Financial Gain
Stealer Malware
Email Phishing
Vietnam

Confidence Assessment

The analysis is based primarily on a single 2025–2026 Palo Alto Networks Unit 42 write‑up and associated article reporting Vampire Bot deliveries to job seekers, providing solid evidence for the actor’s origin (VN), victim profile, and malware. Attribution hinges largely on IP reuse and the Vietnamese context; however, sectoral claims and country list appear broad and lack corroborating data from other independent reports, lowering confidence in those elements. Overall confidence for tactics and tools is moderate to high, while strategic objectives for each targeted sector remain inferred rather than confirmed.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

SHA-256 Hash 13 IPv4 Address 1 Filename 6

References

  1. thehackernews.com — Cited by web research for: said
  2. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  3. unit42.paloaltonetworks.com — Cited by web research for: Mustang Panda
  4. www.thaicert.or.th — Cited by web research for: PowerShell
  5. https://unit42.paloaltonetworks.com/threat-actor-batshadow-vampire-bot/ — Cited by AI analysis.

Intel Summary

20

Techniques

43

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

Data Exfiltration
APT
phishing
espionage
malware
Vietnam
credential-theft
Financial Gain
Stealer Malware
Email Phishing

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
V
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.