Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors PerSwaysion

Description

PerSwaysion is a threat actor known for conducting phishing campaigns targeting high-level executives. They have been active since at least August 2019 and are believed to be based in Vietnam. PerSwaysion has recently updated their techniques, using more direct phishing methods and leveraging Microsoft 365 to steal credentials.

AI Analysis

· 1 week ago

Executive Summary

PerSwaysion is an active threat actor targeting high-level executives via phishing campaigns, particularly focusing on credential theft using Microsoft 365. Originating from Vietnam and active since August 2019, they have evolved their techniques to more direct phishing methods and are suspected to be involved in financial gain or corporate espionage.

Goals & Targeting

PerS waysion's primary objectives likely include financial gain and/or access to sensitive corporate information. They target high-level executives, possibly to gain unauthorized access to corporate networks or sensitive data. The choice of Microsoft 365 as an attack vector suggests a focus on environments where email communication is central and potentially rich in exploitable targets.

Enhanced Description

PerSwaysion is a threat actor known for conducting phishing campaigns that specifically target high-level executives. They were first observed in August 2019 and are believed to be based in Vietnam. The group has recently updated their tactics, employing more direct phishing methods and leveraging Microsoft 365 to steal credentials. PerSwaysion's activities suggest a focus on sectors where sensitive corporate information or financial assets could be accessed through compromised executive accounts. Their operations have been noted in regions such as the Middle East and Europe, indicating a strategic approach to targeting.

Key Capabilities

  • Spear-phishing
  • Social engineering
  • Credential theft via phishing

MITRE ATT&CK Tactics

Initial Access
Credential Access
Exfiltration

ATT&CK Techniques

T1078.001
T1094.001

Software / Tooling

Custom phishing tools
Malware used for credential theft

Campaigns & Victims

PerSwaysion has demonstrated a focus on executives and corporate environments, suggesting a targeted approach to campaign planning. Their use of Microsoft 365 indicates an interest in email-based attack vectors common in many corporate settings.

IOC Patterns

  • Phishing emails with Microsoft 365 links
  • Credential theft via login pages or malicious attachments

Recommended Actions

  • Implement multi-factor authentication (MFA) for Microsoft 365 accounts
  • Conduct regular phishing awareness training for executives
  • Monitor email traffic for suspicious activities related to Microsoft 365

Suggested Tags

Phishing
APT
Credential Theft
Corporate Espionage

Confidence Assessment

Low confidence in some details, such as exact motivation and tools used. Inferred information about their origin and techniques may be subject to change.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Phishing
APT
Credential Theft
Corporate Espionage

Details

Type
Unknown
Country of Origin
V
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.